CVE-2025-55526 is a critical directory traversal vulnerability affecting n8n-workflows (specifically commit ee25413) and associated components like FastAPI, Pydantic, and Uvicorn on Windows 11. With a CVSS score of 9.1, this flaw allows unauthenticated attackers to remotely execute directory traversal via the download_workflow function in api_server.py, leading to high impact on confidentiality and integrity without requiring user interaction. While there are no known public exploits or KEV entries, the vulnerability has garnered significant community discussion with 10 mentions, indicating active interest despite a lack of media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
0.115.14CPE matchmatch criteria | cpe:2.3:a:n8n:fastapi:0.115.14:*:*:*:*:*:*:* | ||
2.11.7CPE matchmatch criteria | cpe:2.3:a:n8n:pydantic:2.11.7:*:*:*:*:*:*:* | ||
0.35.0CPE matchmatch criteria | cpe:2.3:a:n8n:uvicorn:0.35.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.