mediumCVSS 3.7Vulnerability
GHSA-fvfv-ppw4-7h2w
## Impact An end user interacting with a workflow that uses the Guardrail node could craft an input that bypasses the default guardrail instructions. ## Patches The issue has been fixed in n8n version 2.10.0. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Limit access to trusted users. - Review asses the practical impact of guardrail bypasses in your usecase and adjust your workflow accordingly. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Properties
- ghsa_id
- GHSA-fvfv-ppw4-7h2w
- summary
- n8n has a Guardrail Node Bypass
- severity
- medium
- cvss_score
- 3.7
- cve_id
- GHSA-fvfv-ppw4-7h2w
- cvss_vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
- is_ghsa_only
- true
- ghsa_published
- 2026-02-26T22:46:42Z
- source_url
- https://github.com/advisories/GHSA-fvfv-ppw4-7h2w
- ghsa_updated
- 2026-02-26T22:46:43Z
Related Entities (4)
AFFECTS (1)
→[Software]npm/n8n
HAS_WEAKNESS (2)
→[Weakness]Improper Input Validation
→[Weakness]Protection Mechanism Failure
REPORTED_BY (1)
→[Source]GitHub Advisory Database
Explore deeper with Ninja Signal's threat intelligence graph