
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33751 is an LDAP Filter Injection vulnerability in the n8n open-source workflow automation platform, classified as "LDAP Filter Injection in LDAP Node" (GHSA-w83q-mcmx-mh42). A flaw in the LDAP node's filter escape logic allows LDAP metacharacters to pass through unescaped when user-controlled input is interpolated into LDAP search filters via expressions. Affected versions include all n8n releases prior to 1.123.27 (v1 branch), 2.0.0-rc.0 through 2.13.2 (v2 branch), and version 2.14.0 specifically. The vulnerability was published on March 25, 2026, and carries a CVSS v4.0 base score of 6.3 (Medium) and a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, n8n Security Advisory).
The root cause is CWE-90 (Improper Neutralization of Special Elements used in an LDAP Query), where the LDAP node's filter escape logic fails to sanitize LDAP metacharacters (e.g., *, (, ), \, NUL) when user-supplied input is interpolated into LDAP search filter strings via n8n expressions (GitHub Advisory). Exploitation requires a specific precondition: the target n8n workflow must use the LDAP node with user-controlled input (e.g., from a form submission or webhook) passed into search parameters via expressions. An attacker can craft malicious input containing LDAP metacharacters to alter the logical structure of the constructed filter, enabling retrieval of unintended directory records or manipulation of authentication logic within the workflow (n8n Security Advisory).
Successful exploitation allows an unauthenticated attacker to retrieve unintended LDAP records from the connected directory service or bypass authentication checks implemented within the n8n workflow, leading to unauthorized access to sensitive directory information (n8n Security Advisory). The impact is limited to confidentiality and integrity — there is no availability impact — and is constrained to workflows that specifically use the LDAP node with unsanitized external input. Depending on the directory contents and workflow design, exposed data could include user credentials, organizational data, or group memberships stored in the LDAP directory (GitHub Advisory).
No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.019% (5th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for a specific workflow configuration, reducing the overall attack surface (GitHub Advisory).
(&(uid=<input>)(userPassword=<password>)), supply input such as admin)(|(uid=* to alter the filter logic.*, (, ), \) or wildcard patterns.The vulnerability has been patched in n8n versions 1.123.27, 2.13.3, and 2.14.1; users should upgrade to one of these versions or later as the primary remediation (n8n Security Advisory). If immediate upgrading is not possible, the following temporary mitigations should be applied: (1) limit workflow creation and editing permissions to fully trusted users only; (2) disable the LDAP node entirely by adding n8n-nodes-base.ldap to the NODES_EXCLUDE environment variable; and/or (3) avoid passing unvalidated external user input into LDAP node search parameters via expressions. These workarounds do not fully remediate the risk and are intended only as short-term measures (GitHub Advisory).
The vulnerability was reported by security researcher "allsmog" and published by n8n maintainer "Jubke" via GitHub Security Advisories on March 25, 2026 (n8n Security Advisory). No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."