logo

Two Critical Flaws in n8n AI Workflow Automation Platform Allow Complete Takeover

ID: 27c588f4-ef53-5ddc-9b27-75ed58e7914a

STIX ID: report--27c588f4-ef53-5ddc-9b27-75ed58e7914a

Feed Name: Infosecurity Magazine (News)

Threat Score
95/100

Date Published: 2026-02-04

Date Updated: 2026-04-22

...
...

Researchers at Pillar Security reported two maximum-severity (CVSS 10.0) sandbox-escape vulnerabilities in the open-source workflow platform n8n that allow an authenticated user to achieve complete server takeover and steal stored credentials (API keys, cloud provider keys, database passwords, OAuth tokens), potentially impacting AI orchestration integrations (OpenAI, Anthropic, Azure OpenAI, Hugging Face, vector DBs) and shared cloud infrastructure; n8n released version 2.4.0 with fixes in January 2026 and Pillar advised immediate upgrades, rotating encryption keys and credentials, auditing workflows, and monitoring AI workflow behavior.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.