logo

Critical n8n flaws disclosed along with public exploits

ID: fed6d656-cabd-573c-8491-4e669d1e1a88

STIX ID: report--fed6d656-cabd-573c-8491-4e669d1e1a88

Feed Name: Bleeping Computer

Threat Score
80/100

Date Published: 2026-02-04

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

Multiple critical sandbox-escape vulnerabilities in the n8n workflow automation platform (CVE-2026-25049) allow authenticated users who can create or edit workflows to bypass AST-based sanitization, achieve remote code execution, access filesystem and secrets, pivot to cloud accounts, and potentially affect multi-tenant environments. Researchers from Pillar Security, Endor Labs, and SecureLayer7 published technical details and PoCs, n8n released fixes (versions 1.123.17 and 2.5.2/2.4.0), and recommended actions include updating, rotating the N8N_ENCRYPTION_KEY and stored credentials, restricting workflow creation/editing, and hardening deployments; no public exploitation of this CVE was reported though scanning activity against related n8n issues has been observed.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.