Vulnerability Description
n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including client-side commands, directly to the Snowflake SDK without applying n8n's file-access restrictions. An authenticated user with usable Snowflake credentials can upload a local file from the n8n host or overwrite an existing file with a staged one.
Related Weaknesses (CWE)
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-r4j2-j3wm-q689
- https://www.vulncheck.com/advisories/n8n-before-arbitrary-file-read-and-write-vi
FAQ
What is CVE-2026-77080?
CVE-2026-77080 is a documented vulnerability. n8n before 1.123.69, 2.x before 2.33.4, and 2.34.x before 2.34.1 contain an arbitrary file read and write vulnerability in the Snowflake node, which passes free-form Execute Query input, including cli...
How severe is CVE-2026-77080?
CVSS scoring is not yet available for CVE-2026-77080. Check NVD for updates.
Is there a patch for CVE-2026-77080?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.