n8n npm Package Privilege Escalation Threat: What You Need to Know
A confirmed high-severity vulnerability in the n8n npm package allows authenticated users to escalate privileges to instance owner, gaining full administrative control under specific conditions.
What happened
The n8n npm package, versions prior to 1.123.64, 2.29.8, and 2.30.1, contains a critical vulnerability tracked as GHSA-35Q8-9MJ6-WJMF. This issue arises in Enterprise SSO configurations where instance-role provisioning is enabled, permitting SSO-authenticated users to be provisioned as instance owners. Exploiting this vulnerability grants the attacker full administrative control over the n8n instance.
To mitigate this threat, it is recommended to upgrade to n8n version 1.123.64, 2.29.8, or 2.30.1. Organizations utilizing n8n with Enterprise SSO and instance-role provisioning should immediately assess their configurations and apply the necessary updates. For detailed information and remediation steps, consult the primary sources listed below.
Primary sources for this vulnerability include GitHub Security Advisories GHSA-2x35-3fw4-9jr4, GHSA-2xgm-wc4g-5jvg, GHSA-33q9-f52j-gc75, and GHSA-35q8-9mj6-wjmf, as well as an external report from The Hacker News detailing a related sandbox escape vulnerability.
How 0Day mitigates this
n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.