n8n-workflows Main Commit ee25413 allows attackers to execute a directory traversal via the download_workflow function within api_server.py
2025-08-26T14:15:41.410
2025-09-15T19:38:14.897
Analyzed
CVSSv3.1: 9.1 (CRITICAL)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | n8n | fastapi | 0.115.14 | Yes |
| Application | n8n | pydantic | 2.11.7 | Yes |
| Application | n8n | uvicorn | 0.35.0 | Yes |
| Operating System | microsoft | windows_11 | - | No |