CVE-2026-77068EPSS p59.2%
CVE-2026-77068CVE-2026-77068
n8n / n8n
Description
n8n before 2.33.4 and 2.34.x before 2.34.1 contain a remote code execution vulnerability in the @n8n/workflow-sdk node-schema loader used for MCP node-schema loading. The loader derives a node's schema module path directly from the attacker-supplied node type string without validating path-traversal sequences. An authenticated user with global:member privileges can reference malicious files via path traversal, causing code execution in the n8n main process.
Scoring
| CVSS | 8.8 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 0.93% probability of exploitation · percentile 59.2% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-01 |