logo

More Critical Flaws on n8n Could Compromise Customer Security

ID: 8d930398-bf83-5434-b399-8e77da9b9ad8

STIX ID: report--8d930398-bf83-5434-b399-8e77da9b9ad8

Feed Name: Dark Reading

Threat Score
80/100

Date Published: 2026-01-29

Date Updated: 2026-04-21

Author: Jai Vijayan, Contributing Writer

...
...

Researchers disclosed two serious vulnerabilities in the n8n workflow automation platform — CVE-2026-1470 (CVSS 9.9, sandbox escape via deprecated JavaScript feature) and CVE-2026-0863 (Python execution flaw on server) — that allow attackers who can create workflows to achieve full remote code execution, access credentials and potentially pivot to other systems; multiple versions are affected and vendors recommend disconnecting, enforcing strong authentication, and minimizing execution privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.