Skip to content

Add n8n-workflow to affected packages for GHSA-vpcf-gvg4-6qwr - #8970

Open
brittf619 wants to merge 1 commit into
github:brittf619/advisory-improvement-8970from
brittf619:ghsa-vpcf-gvg4-6qwr-add-n8n-workflow
Open

Add n8n-workflow to affected packages for GHSA-vpcf-gvg4-6qwr#8970
brittf619 wants to merge 1 commit into
github:brittf619/advisory-improvement-8970from
brittf619:ghsa-vpcf-gvg4-6qwr-add-n8n-workflow

Conversation

@brittf619

@brittf619 brittf619 commented Aug 3, 2026

Copy link
Copy Markdown

Summary

This advisory currently lists only the n8n umbrella package under affected. The vulnerable code, the expression compiler's AST rewriter, where a missing case allowed identifiers to slip through untransformed, lives in n8n-workflow, which is published to npm as an independent package. Downstream consumers of GHSA/OSV data miss the sub-package attribution and undercount exposure when n8n-workflow is resolved without the umbrella package.

The fixed versions differ from the umbrella n8n package (1.123.22 / 2.9.3 / 2.10.1) because n8n-workflow versions independently within the monorepo.

Verification

The n8n-workflow version at each umbrella fix tag was confirmed from packages/workflow/package.json in the n8n monorepo:

n8n@1.123.22 → n8n-workflow@1.120.9
n8n@2.9.3 → n8n-workflow@2.9.1
n8n@2.10.1 → n8n-workflow@2.10.1

Related PRs

@github-actions
github-actions Bot changed the base branch from main to brittf619/advisory-improvement-8970 August 3, 2026 22:01
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant