Home

Description

n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the same Node.js process (for example, data from prior requests, tasks, secrets, or tokens), resulting in potential information disclosure. This issue has been patched in version 1.114.3.

PUBLISHED Reserved 2025-10-03 | Published 2026-02-04 | Updated 2026-02-05 | Assigner GitHub_M




HIGH: 7.7CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Problem types

CWE-668: Exposure of Resource to Wrong Sphere

CWE-200: Exposure of Sensitive Information to an Unauthorized Actor

Product status

>= 1.65.0, < 1.114.3
affected

References

github.com/...io/n8n/security/advisories/GHSA-49mx-fj45-q3p6

github.com/...ommit/2c4c2953199733c791f739a40879ae31ca129aba

cve.org (CVE-2025-61917)

nvd.nist.gov (CVE-2025-61917)

Download JSON