
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-61917 is an unsafe buffer allocation vulnerability in n8n, an open-source workflow automation platform, that allows authenticated users to disclose residual in-process memory. The flaw exists in the task runner component from version 1.65.0 up to (but not including) 1.114.3, where the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() exposes uninitialized memory that may contain sensitive data from the same Node.js process. It was published on February 4, 2026, with a CVSS v3.1 base score of 7.7 (High) (Github Advisory, n8n Security Advisory).
The root cause is the exposure of Node.js's Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() APIs within the task runner sandbox, classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor) and CWE-668 (Exposure of Resource to Wrong Sphere). Unlike Buffer.alloc(), these functions do not zero-fill allocated memory, meaning the returned buffer may contain residual heap data from the same Node.js process — including data from prior requests, tasks, API secrets, or session tokens. Exploitation requires two conditions to be met simultaneously: Task Runners must be enabled (N8N_RUNNERS_ENABLED=true, which defaults to false) and the Code Node must be enabled (default: true). The fix, introduced in commit 2c4c295, wraps the Buffer object in a Proxy that redirects calls to allocUnsafe and allocUnsafeSlow to the safe Buffer.alloc (zero-filling) equivalent (n8n Security Advisory, Patch Commit).
Successful exploitation allows an authenticated low-privileged attacker to read uninitialized memory from within the n8n Node.js process, potentially exposing highly sensitive data such as API tokens, credentials, session data, secrets, or data from other users' workflow executions. The confidentiality impact is rated High with a changed scope, meaning data from components beyond the attacker's direct access (e.g., other users' tasks or system-level secrets) can be leaked. There is no integrity or availability impact, but the exposure of credentials could enable lateral movement or privilege escalation in downstream systems (Github Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the time of disclosure (Github Advisory). The EPSS score is approximately 0.021% (6th percentile), indicating a low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to authenticated users with access to the Code Node in deployments where Task Runners are explicitly enabled, limiting the attack surface.
N8N_RUNNERS_ENABLED=true and the Code Node enabled (default).Buffer.allocUnsafe(N) with a large buffer size (e.g., Buffer.allocUnsafe(65536)) to maximize the amount of uninitialized memory captured.return [{ json: { data: Buffer.allocUnsafe(65536).toString('hex') } }], which will include raw process memory that may contain secrets, tokens, or data from prior tasks.Buffer.allocUnsafe or Buffer.allocUnsafeSlow with large size arguments; repeated workflow executions by a single low-privileged user in a short timeframe.Buffer.allocUnsafe() or Buffer.allocUnsafeSlow() calls, especially those returning buffer contents as output data.Upgrade n8n to version 1.114.3 or later, which routes all buffer allocations through Buffer.alloc (zero-filling) and removes access to unsafe buffer functions from the task runner sandbox (n8n Security Advisory). If an immediate upgrade is not possible, two workarounds are recommended: (1) disable the Code Node by adding n8n-nodes-base.code to the NODES_EXCLUDE environment variable, or (2) run Task Runners in external mode so untrusted code executes in a separate sidecar container isolated from the main n8n process, significantly reducing the risk of in-process memory disclosure. Restricting access to workflow execution features to trusted users only provides additional defense-in-depth.
The vulnerability was covered by CSO Online as part of a broader report on multiple n8n security issues, and The Hacker News referenced it in coverage of n8n flaws (CSO Online). Belgium's Centre for Cybersecurity (CCB) issued an advisory warning about multiple critical vulnerabilities in n8n, including this issue (CCB Advisory). Community reaction has been moderate, with security researchers noting the practical constraint that Task Runners must be explicitly enabled, limiting the real-world attack surface.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."