
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27496 is an in-process memory disclosure vulnerability in n8n, an open-source workflow automation platform, affecting its JavaScript Task Runner component. An authenticated user with workflow creation or modification permissions can allocate uninitialized memory buffers that may contain residual Node.js process data — including secrets, tokens, and prior request data — leading to sensitive information disclosure. The vulnerability was published on March 25, 2026, and affects n8n versions prior to 1.123.22, versions 2.0.0-rc.0 through 2.9.3 (exclusive), and version 2.10.0. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-908 (Use of Uninitialized Resource): the JavaScript Task Runner in n8n allows authenticated users to allocate Buffer objects in Node.js without proper initialization, a known pitfall where Buffer.allocUnsafe() or similar APIs can expose previously used memory regions. Because Node.js reuses heap memory across operations within the same process, these uninitialized buffers may contain residual data from prior requests, workflow executions, secrets, or authentication tokens. Exploitation requires the Task Runner feature to be enabled (N8N_RUNNERS_ENABLED=true), and the attacker must have authenticated access with workflow creation or editing privileges. The vulnerability was reported by researcher c0rydoras (GitHub Advisory, n8n Security Advisory).
Successful exploitation results in high confidentiality impact with no integrity or availability impact. An attacker can read arbitrary in-process memory from the n8n Node.js process, potentially exposing API keys, authentication tokens, secrets stored in environment variables, and data from other users' workflow executions processed by the same instance. In external runner mode (N8N_RUNNERS_MODE=external), the exposure is limited to data within the isolated runner process, reducing but not eliminating the risk of cross-tenant or cross-workflow data leakage (GitHub Advisory, n8n Security Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.032–0.041% (13th percentile), indicating a low near-term exploitation probability. Exploitation requires authenticated access with workflow editing privileges and the Task Runner feature to be explicitly enabled, which limits the attack surface (GitHub Advisory).
N8N_RUNNERS_ENABLED=true is set on the target n8n instance, as the vulnerability only exists when this feature is active.Buffer of a specified size (e.g., Buffer.allocUnsafe(4096)) and returns or exfiltrates its contents, exploiting Node.js memory reuse behavior.Buffer allocation (e.g., Buffer.allocUnsafe, Buffer.alloc with no initialization); unexpected workflow executions by low-privilege users.Patches are available in n8n versions 1.123.22, 2.9.3, and 2.10.1 — users should upgrade to one of these versions or later as the primary remediation. If immediate upgrade is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and/or switch to external runner mode (N8N_RUNNERS_MODE=external) to isolate the runner process and limit the scope of any memory disclosure. Note that these workarounds do not fully eliminate the risk and are intended only as short-term measures (n8n Security Advisory, GitHub Advisory).
The advisory was published by n8n maintainer "Jubke" on GitHub on March 25, 2026, with credit to researcher c0rydoras for the report. No significant broader media coverage, vendor statements beyond the official advisory, or notable community commentary have been identified at this time (n8n Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."