logo

New n8n Vulnerability Allows Attackers to Execute Arbitrary Commands

ID: 36a96c6c-31b2-5db9-8fe9-e7a8d0e6fb15

STIX ID: report--36a96c6c-31b2-5db9-8fe9-e7a8d0e6fb15

Feed Name: GBHackers

Threat Score
75/100

Date Published: 2026-01-06

Date Updated: 2026-04-22

Author: Divya

...
...

A critical sandbox-bypass vulnerability (CVE-2025-68668, CVSS 9.1) in n8n's Pyodide-based Python Code Node allows authenticated users with workflow creation/modification privileges to execute arbitrary system commands; versions 1.0.0 through 1.999.999 are affected, n8n 2.0.0 contains a full fix, and workarounds (disabling the Code Node or disabling Python support / enabling the native Python runner) are available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.