CVE-2025-55526
Executive Summary
CVE-2025-55526 exposes a directory traversal flaw in n8n-workflows’ download_workflow endpoint (api_server.py). An unauthenticated attacker can craft a request to read arbitrary files on the host, potentially leaking sensitive data or credentials. The vulnerability is not yet listed in CISA KEV but poses a significant risk to systems running the affected n8n version.
Authoritative CVE Metadata - CVSS Base Score: 9.1 (CRITICAL) - Published: 2025-08-26T14:15:41.410 - Last Modified: 2026-08-20T13:12:43.340
Original Description: n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
"To give hope to someone occurs when you teach them how to use the tools to do it for themselves."
— Byron Pulsifer