GHSA-w867-jm58-p9pv: n8n: Authenticated Users Can Exhaust Temporary Disk Storage via Data-Table File Uploads
Summary
In n8n (a workflow automation tool), authenticated users can upload files repeatedly to bypass upload limits, causing temporary files to pile up on the server's disk until the automatic cleanup runs, potentially filling the disk completely. This happens because the system doesn't properly track files already stored in the shared temporary directory.
Solution / Mitigation
Users should upgrade to the patched version once available. If upgrading immediately is not possible, administrators can temporarily: restrict n8n access to fully trusted users only, set `uploadMaxFileSize` to a low value to limit individual upload size, and monitor and alert on disk usage in the n8n temporary upload directory. The source notes these workarounds do not fully remediate the risk and should only be used as short-term measures.
Vulnerability Details
EPSS: 0.2%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-47482: NVIDIA Triton Inference Server for Linux contains a vulnerability where an attacker can cause missing release of memory
CVE-2022-29200: TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, the implem
Original source: https://github.com/advisories/GHSA-w867-jm58-p9pv
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%