SCA: security update for n8n (GHSA-j4p8-h8mh-rh8q)

medium Tenable Self-Hosted Container Security Plugin ID 436491

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- n8n is an open source workflow automation platform. Prior to version 2.0.0, in self-hosted n8n instances
where the Code node runs in legacy (non-task-runner) JavaScript execution mode, authenticated users with
workflow editing access can invoke internal helper functions from within the Code node. This allows a
workflow editor to perform actions on the n8n host with the same privileges as the n8n process, including:
reading files from the host filesystem (subject to any file-access restrictions configured on the instance
and OS/container permissions), and writing files to the host filesystem (subject to the same
restrictions). This issue has been patched in version 2.0.0. Workarounds for this issue involve limiting
file operations by setting N8N_RESTRICT_FILE_ACCESS_TO to a dedicated directory (e.g., ~/.n8n-files) and
ensure it contains no sensitive data, keeping N8N_BLOCK_FILE_ACCESS_TO_N8N_FILES=true (default) to block
access to .n8n and user-defined config files, and disabling high-risk nodes (including the Code node)
using NODES_EXCLUDE if workflow editors are not fully trusted. (CVE-2025-68697)

See Also

https://github.com/advisories/GHSA-j4p8-h8mh-rh8q

Plugin Details

Severity: Medium

ID: 436491

Version: Revision 1.11

Type: Local

Family: SCA Checks

Published: 12/26/2025

Updated: 7/6/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Low

Score: 2.1

Percentile: 7.8

Vendor

Vendor Severity: High

CVSS v2

Risk Factor: Medium

Base Score: 5.5

Temporal Score: 4.1

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS Score Source: CVE-2025-68697

CVSS v3

Risk Factor: Medium

Base Score: 5.4

Temporal Score: 4.7

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N

Temporal Vector: CVSS:3.0/E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Patch Publication Date: 12/26/2025

Vulnerability Publication Date: 12/26/2025

Reference Information

CVE: CVE-2025-68697