Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Path Injection in n8n Elasticsearch and ElasticSecurity Nodes

The Elasticsearch and ElasticSecurity nodes in n8n allowed path injection attacks through unencoded identifiers, enabling attackers to access unintended endpoints or documents using stored Elasticsearch credentials. The vulnerability was patched in versions 1.123.76, 2.37.7, and 2.38.2.

Disclosed 10 September 2026 · Record updated 13 September 2026

Impact

Attackers could manipulate Elasticsearch and ElasticSecurity node operations to access unintended indices or cluster administration endpoints using stored credentials.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-f2cp-m7mv-8jpv