logo

Critical 9.4 CVSS RCE Flaws in n8n Turn Workflows into Backdoors

ID: c2337915-6adf-5eca-a8ef-8a99526bea35

STIX ID: report--c2337915-6adf-5eca-a8ef-8a99526bea35

Feed Name: securityonline.info

Threat Score
78/100

Date Published: 2026-03-27

Date Updated: 2026-04-23

Author: Ddos

...
...

Security researchers disclosed two critical RCE-capable vulnerabilities in the n8n workflow automation platform: CVE-2026-33660 (Merge node using AlaSQL, allowing local file reads and potential remote code execution) and a Prototype Pollution flaw in the GSuiteAdmin node that can enable arbitrary code execution. Patches have been released across multiple release branches; administrators are urged to update immediately or apply mitigations such as restricting workflow creation/editing to trusted users and disabling the affected nodes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.