CVE-2026-33751: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33751 is an LDAP Filter Injection vulnerability in the n8n open-source workflow automation platform, classified as "LDAP Filter Injection in LDAP Node" (GHSA-w83q-mcmx-mh42). A flaw in the LDAP node's filter escape logic allows LDAP metacharacters to pass through unescaped when user-controlled input is interpolated into LDAP search filters via expressions. Affected versions include all n8n releases prior to 1.123.27 (v1 branch), 2.0.0-rc.0 through 2.13.2 (v2 branch), and version 2.14.0 specifically. The vulnerability was published on March 25, 2026, and carries a CVSS v4.0 base score of 6.3 (Medium) and a CVSS v3.1 base score of 4.8 (Medium) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is CWE-90 (Improper Neutralization of Special Elements used in an LDAP Query), where the LDAP node's filter escape logic fails to sanitize LDAP metacharacters (e.g., *, (, ), \, NUL) when user-supplied input is interpolated into LDAP search filter strings via n8n expressions (GitHub Advisory). Exploitation requires a specific precondition: the target n8n workflow must use the LDAP node with user-controlled input (e.g., from a form submission or webhook) passed into search parameters via expressions. An attacker can craft malicious input containing LDAP metacharacters to alter the logical structure of the constructed filter, enabling retrieval of unintended directory records or manipulation of authentication logic within the workflow (n8n Security Advisory).

Impact

Successful exploitation allows an unauthenticated attacker to retrieve unintended LDAP records from the connected directory service or bypass authentication checks implemented within the n8n workflow, leading to unauthorized access to sensitive directory information (n8n Security Advisory). The impact is limited to confidentiality and integrity — there is no availability impact — and is constrained to workflows that specifically use the LDAP node with unsanitized external input. Depending on the directory contents and workflow design, exposed data could include user credentials, organizational data, or group memberships stored in the LDAP directory (GitHub Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of disclosure (GitHub Advisory). The EPSS score is approximately 0.019% (5th percentile), indicating a low near-term probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained by the requirement for a specific workflow configuration, reducing the overall attack surface (GitHub Advisory).

Exploitation steps

  1. Reconnaissance: Identify publicly accessible n8n instances running affected versions (prior to 1.123.27, 2.13.3, or 2.14.1) that expose forms or webhooks connected to LDAP-backed workflows.
  2. Identify vulnerable input vector: Locate a form or webhook endpoint in the n8n workflow that accepts user-controlled input and passes it via an expression into the LDAP node's search filter parameter (e.g., a login or user-lookup form).
  3. Craft malicious LDAP filter payload: Inject LDAP metacharacters into the input field to manipulate the search filter. For example, to bypass an authentication check that constructs (&(uid=<input>)(userPassword=<password>)), supply input such as admin)(|(uid=* to alter the filter logic.
  4. Submit the payload: Send the crafted input via the exposed form or webhook HTTP request to the n8n instance.
  5. Achieve objective: The manipulated LDAP filter is forwarded to the directory server, potentially returning unintended records (e.g., all users) or satisfying an authentication condition that should not be met, granting unauthorized access or data exposure (n8n Security Advisory).

Indicators of compromise

  • Network: Unusual or malformed LDAP search requests originating from the n8n server to the LDAP/Active Directory server, particularly filters containing unexpected metacharacters (*, (, ), \) or wildcard patterns.
  • Logs: n8n workflow execution logs showing LDAP node invocations with input values containing LDAP special characters; LDAP server access logs showing broad or unexpected search results returned for queries from the n8n service account.
  • Application: n8n workflow audit logs reflecting unexpected successful executions of LDAP-backed authentication or lookup workflows, especially from unfamiliar source IPs or at unusual times.

Mitigation and workarounds

The vulnerability has been patched in n8n versions 1.123.27, 2.13.3, and 2.14.1; users should upgrade to one of these versions or later as the primary remediation (n8n Security Advisory). If immediate upgrading is not possible, the following temporary mitigations should be applied: (1) limit workflow creation and editing permissions to fully trusted users only; (2) disable the LDAP node entirely by adding n8n-nodes-base.ldap to the NODES_EXCLUDE environment variable; and/or (3) avoid passing unvalidated external user input into LDAP node search parameters via expressions. These workarounds do not fully remediate the risk and are intended only as short-term measures (GitHub Advisory).

Community reactions

The vulnerability was reported by security researcher "allsmog" and published by n8n maintainer "Jubke" via GitHub Security Advisories on March 25, 2026 (n8n Security Advisory). No significant broader media coverage or notable community commentary beyond the advisory itself has been identified at this time.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management