logo

Critical n8n Vulnerability Enables System Command Execution Via Weaponized Workflows

ID: 207e32f8-e3b9-5e59-ba09-90469b579161

STIX ID: report--207e32f8-e3b9-5e59-ba09-90469b579161

Feed Name: cybersecurityNews.com

Threat Score
75/100

Date Published: 2026-02-05

Date Updated: 2026-04-21

Author: Guru Baran

...
...

A critical RCE vulnerability was discovered in n8n's expression evaluation engine that permits authenticated users with workflow creation/modification rights to inject and execute arbitrary system commands via weaponized workflow expressions; maintainers published emergency patches and administrators are urged to upgrade or apply mitigations to reduce attack surface.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.