CVE-2025-61917
n8n is an open source workflow automation platform. From version 1.65.0 to before 1.114.3, the use of Buffer.allocUnsafe() and Buffer.allocUnsafeSlow() in the task runner allowed untrusted code to allocate uninitialized memory. Such uninitialized buffers could contain residual data from within the same Node.js process (for example, data from prior requests, tasks, secrets, or tokens), resulting in potential information disclosure. This issue has been patched in version 1.114.3.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.7
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
- EPSS probability
- 0.37%
- CWE
- CWE-668, CWE-200
- Published
- 2026-02-04
- Last modified
- 2026-03-12
Affected products
- n8n-io n8n
Weakness type
Related vulnerabilities
- CVE-2026-85053 — Improper resource exposure in CacheStorage in Google Chrome prior to 152.0.7977.82 allowed a remote...
- CVE-2026-82652 — SiYuan before v3.8.1 Information Disclosure via Publish Access
- CVE-2026-82650 — SiYuan before v3.8.1 Path Traversal via /api/template/render
- CVE-2026-72924 — GitHub CLI: `gh codespace ports forward` exposes forwarded services on all network interfaces by default
- CVE-2026-79068 — Improper resource exposure in StreamsAPI in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-79031 — Improper resource exposure in Preload in Google Chrome prior to 152.0.7977.65 allowed a remote...
- CVE-2026-59308 — Semantic Cache Cross-Tenant Isolation Bypass via SHA-256 Truncation
- CVE-2026-73843 — OpenChoreo: Unauthenticated access to data-plane operations via OpenChoreo cluster-gateway management APIs