Critical 9.4 CVSS RCE Flaws in n8n Turn Workflows into Backdoors
ID: c2337915-6adf-5eca-a8ef-8a99526bea35
STIX ID: report--c2337915-6adf-5eca-a8ef-8a99526bea35
Feed Name: securityonline.info
Security researchers disclosed two critical RCE-capable vulnerabilities in the n8n workflow automation platform: CVE-2026-33660 (Merge node using AlaSQL, allowing local file reads and potential remote code execution) and a Prototype Pollution flaw in the GSuiteAdmin node that can enable arbitrary code execution. Patches have been released across multiple release branches; administrators are urged to update immediately or apply mitigations such as restricting workflow creation/editing to trusted users and disabling the affected nodes.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
