logo

n8n Vulnerability Allows Remote Attackers to Hijack Systems via Malicious Workflow Execution

ID: 640d2953-9f90-5a72-ba79-acfd245e2d96

STIX ID: report--640d2953-9f90-5a72-ba79-acfd245e2d96

Feed Name: GBHackers

Threat Score
80/100

Date Published: 2026-02-05

Date Updated: 2026-04-22

Author: Divya

...
...

n8n has released urgent security updates for CVE-2026-25049, a critical remote code execution vulnerability in its expression evaluation sandbox that permits authenticated, low-privilege users who can create or edit workflows to escape the application context and execute system commands. Affected versions (< 1.123.17 and < 2.5.2) were patched in 1.123.17 and 2.5.2; administrators are urged to upgrade immediately or apply mitigations such as restricting workflow editing permissions and hardening the runtime environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.