logo

New sandbox escape flaw exposes n8n instances to RCE attacks

ID: 88864b04-aef0-5d34-a75c-746e83dec33e

STIX ID: report--88864b04-aef0-5d34-a75c-746e83dec33e

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-01-28

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Two high-severity sandbox-escape vulnerabilities in the n8n workflow automation platform (CVE-2026-1470 — JavaScript AST escape, and CVE-2026-0863 — Python AST escape) can lead to full remote code execution on self-hosted instances; CVE-2026-1470 scored 9.9 and requires authentication to exploit, while both issues have been patched in specific n8n releases and the n8n cloud is already remediated, but many self-hosted deployments remain exposed so immediate upgrading is recommended.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.