PT-2026-5931 · N8N · N8N

CVE-2025-61917

·

Published

2026-02-04

·

Updated

2026-02-18

CVSS v3.1

7.7

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions n8n versions 1.65.0 through 1.114.2
Description n8n is a workflow automation platform. The use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. This could result in information disclosure, as uninitialized buffers might contain residual data from the Node.js process, such as prior requests, tasks, secrets, or tokens.
Recommendations Update to version 1.114.3 or later.

Exploit

Fix

Information Disclosure

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2026-02183
CVE-2025-61917
GHSA-49MX-FJ45-Q3P6

Affected Products

N8N