logo

Sandbox Shattered: Critical n8n Flaw (CVSS 9.9) Allows Remote Code Execution

ID: 9d2a3270-570c-592f-8790-34efccb7a9b8

STIX ID: report--9d2a3270-570c-592f-8790-34efccb7a9b8

Feed Name: securityonline.info

Threat Score
85/100

Date Published: 2026-01-28

Date Updated: 2026-04-23

Author: Ddos

...
...

A critical RCE vulnerability (CVE-2026-1470, CVSS 9.9) in n8n's Expression evaluation system allows authenticated users to bypass sandboxing and execute arbitrary OS commands on the server; a public PoC demonstrates using the constructor property to invoke child_process.execSync, and administrators are urged to patch affected versions immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.