Skip to content

fix(Execute Sub-workflow Node): Don't expose the file contens when reading the workflow from a file and it's not valid JSON #16416

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Open
wants to merge 2 commits into
base: master
Choose a base branch
from

Conversation

RomanDavydchuk
Copy link
Contributor

@RomanDavydchuk RomanDavydchuk commented Jun 17, 2025

Summary

Update the error message thrown by the Execute Workflow Node to not include the file contents when it tries to read a workflow from a file that is not actually JSON

Before:
image
After:
image

Related to node v1 and v1.1, since the option to read a workflow from a file was removed in v1.2

Related Linear tickets, Github issues, and Community forum posts

https://linear.app/n8n/issue/NODE-3007/execute-workflow-node-local-file-read-vulnerability

Review / Merge checklist

  • PR title and summary are descriptive. (conventions)
  • Docs updated or follow-up ticket created.
  • Tests included.
  • PR Labeled with release/backport (if the PR is an urgent fix that needs to be backported)

@RomanDavydchuk RomanDavydchuk changed the title fix(Execute Workflow Node): Don't expose the file contens when reading the workflow from a file and it's not valid JSON fix(Execute Sub-workflow Node): Don't expose the file contens when reading the workflow from a file and it's not valid JSON Jun 17, 2025
Copy link

codecov bot commented Jun 17, 2025

Codecov Report

All modified and coverable lines are covered by tests ✅

📢 Thoughts on this report? Let us know!

@n8n-assistant n8n-assistant bot added n8n team Authored by the n8n team node/improvement New feature or request labels Jun 17, 2025
@RomanDavydchuk RomanDavydchuk marked this pull request as ready for review June 17, 2025 07:37
@dana-gill dana-gill requested a review from elsmr June 17, 2025 07:38
Copy link
Contributor

@cubic-dev-ai cubic-dev-ai bot left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

cubic reviewed 2 files and found no issues. Review PR in cubic.dev.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
n8n team Authored by the n8n team node/improvement New feature or request
Projects
None yet
Development

Successfully merging this pull request may close these issues.

1 participant