logo

Critical Zero-Click Flaw in n8n Allows Full Server Compromise

ID: 42bd7111-a2e5-5111-8cb7-ff67cb36d08f

STIX ID: report--42bd7111-a2e5-5111-8cb7-ff67cb36d08f

Feed Name: Infosecurity Magazine (News)

Threat Score
90/100

Date Published: 2026-03-12

Date Updated: 2026-04-22

...
...

Researchers at Pillar Security disclosed two critical vulnerabilities in n8n (CVE-2026-27493 and CVE-2026-27577) that permit remote code execution and sandbox escape. CVE-2026-27493 is an unauthenticated, zero-click double-evaluation bug in Form nodes that can run arbitrary shell commands via public form inputs, and CVE-2026-27577 is a sandbox escape in the expression compiler allowing authenticated attackers to achieve full RCE and read the N8N_ENCRYPTION_KEY to decrypt stored credentials. Both cloud and self-hosted instances are affected; n8n Cloud likely received automated patches while self-hosted users are urged to upgrade to the specified patched versions and rotate stored credentials.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.