NPM · JULY 2026 · CONFIRMED

n8n npm Package Privilege Escalation Threat: What You Need to Know

GHSA-35Q8-9MJ6-WJMFSeverity: HIGH

A confirmed high-severity vulnerability in the n8n npm package allows authenticated users to escalate privileges to instance owner, gaining full administrative control under specific conditions.

What happened

The n8n npm package, versions prior to 1.123.64, 2.29.8, and 2.30.1, contains a critical vulnerability tracked as GHSA-35Q8-9MJ6-WJMF. This issue arises in Enterprise SSO configurations where instance-role provisioning is enabled, permitting SSO-authenticated users to be provisioned as instance owners. Exploiting this vulnerability grants the attacker full administrative control over the n8n instance.

To mitigate this threat, it is recommended to upgrade to n8n version 1.123.64, 2.29.8, or 2.30.1. Organizations utilizing n8n with Enterprise SSO and instance-role provisioning should immediately assess their configurations and apply the necessary updates. For detailed information and remediation steps, consult the primary sources listed below.

Primary sources for this vulnerability include GitHub Security Advisories GHSA-2x35-3fw4-9jr4, GHSA-2xgm-wc4g-5jvg, GHSA-33q9-f52j-gc75, and GHSA-35q8-9mj6-wjmf, as well as an external report from The Hacker News detailing a related sandbox escape vulnerability.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats