logo

Critical n8n Flaw Expose Automation Nodes to Full RCE

ID: cfc1e1cb-762a-53d4-8b0a-9bf6b861df1e

STIX ID: report--cfc1e1cb-762a-53d4-8b0a-9bf6b861df1e

Feed Name: Cyber Press

Threat Score
80/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Lucas Martin

...
...

Three critical vulnerabilities were published for the n8n workflow automation platform that allow authenticated users with low privileges to achieve remote code execution, read arbitrary files, or bypass a prior patch via prototype pollution and argument injection. Affected versions are older than 1.123.43, 2.20.7, and 2.22.1; n8n released fixes and recommends immediate upgrades or mitigations (restricting workflow permissions and disabling affected nodes) due to the high-impact, network-exploitable nature of the flaws.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.