Path Injection in n8n Elasticsearch and ElasticSecurity Nodes
The Elasticsearch and ElasticSecurity nodes in n8n allowed path injection attacks through unencoded identifiers, enabling attackers to access unintended endpoints or documents using stored Elasticsearch credentials. The vulnerability was patched in versions 1.123.76, 2.37.7, and 2.38.2.
Disclosed 10 September 2026 · Record updated 13 September 2026
Impact
Attackers could manipulate Elasticsearch and ElasticSecurity node operations to access unintended indices or cluster administration endpoints using stored credentials.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-f2cp-m7mv-8jpv
