CVE-2025-61917: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2025-61917 is an unsafe buffer allocation vulnerability in n8n, an open-source workflow automation platform, that allows authenticated users to disclose residual in-process memory. The flaw exists in the task runner component from version 1.65.0 up to (but not including) 1.114.3, where the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() exposes uninitialized memory that may contain sensitive data from the same Node.js process. It was published on February 4, 2026, with a CVSS v3.1 base score of 7.7 (High) (Github Advisory, n8n Security Advisory).

Technical details

The root cause is the exposure of Node.js's Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() APIs within the task runner sandbox, classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-668 (Exposure of Resource to Wrong Sphere). Unlike Buffer.alloc(), these functions do not zero-fill allocated memory, meaning the returned buffer may contain residual heap data from the same Node.js process — including data from prior requests, tasks, API secrets, or session tokens. Exploitation requires two conditions to be met simultaneously: Task Runners must be enabled (N8N_RUNNERS_ENABLED=true, which defaults to false) and the Code Node must be enabled (default: true). The fix, introduced in commit 2c4c295, wraps the Buffer object in a Proxy that redirects calls to allocUnsafe and allocUnsafeSlow to the safe Buffer.alloc (zero-filling) equivalent (n8n Security Advisory, Patch Commit).

Impact

Successful exploitation allows an authenticated low-privileged attacker to read uninitialized memory from within the n8n Node.js process, potentially exposing highly sensitive data such as API tokens, credentials, session data, secrets, or data from other users' workflow executions. The confidentiality impact is rated High with a changed scope, meaning data from components beyond the attacker's direct access (e.g., other users' tasks or system-level secrets) can be leaked. There is no integrity or availability impact, but the exposure of credentials could enable lateral movement or privilege escalation in downstream systems (Github Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to authenticated users with access to the Code Node in deployments where Task Runners are explicitly enabled, limiting the attack surface.

Exploitation steps

  1. Identify a vulnerable deployment: Confirm the target n8n instance is running version 1.65.0–1.114.2 with both N8N_RUNNERS_ENABLED=true and the Code Node enabled (default).
  2. Authenticate: Log in to the n8n instance with any valid low-privileged user account that has access to create or execute workflows.
  3. Create a malicious workflow: Create a new workflow containing a Code Node with a JavaScript payload that calls Buffer.allocUnsafe(N) with a large buffer size (e.g., Buffer.allocUnsafe(65536)) to maximize the amount of uninitialized memory captured.
  4. Exfiltrate memory contents: Return the buffer contents as workflow output, e.g., return [{ json: { data: Buffer.allocUnsafe(65536).toString('hex') } }], which will include raw process memory that may contain secrets, tokens, or data from prior tasks.
  5. Analyze the output: Parse the returned hex or string data for recognizable patterns such as JWT tokens, API keys, or other structured secrets from the Node.js process heap (n8n Security Advisory, Patch Commit).

Indicators of compromise

  • Logs: n8n workflow execution logs showing Code Node executions containing calls to Buffer.allocUnsafe or Buffer.allocUnsafeSlow with large size arguments; repeated workflow executions by a single low-privileged user in a short timeframe.
  • Workflow Artifacts: Workflows containing Code Node scripts with Buffer.allocUnsafe() or Buffer.allocUnsafeSlow() calls, especially those returning buffer contents as output data.
  • Network: Unusual outbound data transfers from the n8n server following workflow executions, potentially indicating exfiltration of extracted memory contents.
  • Process Behavior: Elevated memory read activity within the n8n Node.js process correlated with Code Node task runner executions.

Mitigation and workarounds

Upgrade n8n to version 1.114.3 or later, which routes all buffer allocations through Buffer.alloc (zero-filling) and removes access to unsafe buffer functions from the task runner sandbox (n8n Security Advisory). If an immediate upgrade is not possible, two workarounds are recommended: (1) disable the Code Node by adding n8n-nodes-base.code to the NODES_EXCLUDE environment variable, or (2) run Task Runners in external mode so untrusted code executes in a separate sidecar container isolated from the main n8n process, significantly reducing the risk of in-process memory disclosure. Restricting access to workflow execution features to trusted users only provides additional defense-in-depth.

Community reactions

The vulnerability was covered by CSO Online as part of a broader report on multiple n8n security issues, and The Hacker News referenced it in coverage of n8n flaws (CSO Online). Belgium's Centre for Cybersecurity (CCB) issued an advisory warning about multiple critical vulnerabilities in n8n, including this issue (CCB Advisory). Community reaction has been moderate, with security researchers noting the practical constraint that Task Runners must be explicitly enabled, limiting the real-world attack surface.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management