logo

Critical and High Severity n8n Sandbox Flaws Allow RCE

ID: b96327f7-a171-5a8a-969a-fe934d0b3521

STIX ID: report--b96327f7-a171-5a8a-969a-fe934d0b3521

Feed Name: Infosecurity Magazine (News)

Threat Score
78/100

Date Published: 2026-01-28

Date Updated: 2026-04-22

...
...

Two critical sandbox-escape vulnerabilities in the n8n workflow automation platform (CVE-2026-1470 for JavaScript, CVSS 9.9; CVE-2026-0863 for Python, CVSS 8.5) allow authenticated users who can create or modify workflows to bypass JavaScript and Python sandboxing and achieve remote code execution in the main n8n process. Patches are available in specified 1.x/2.x releases; unpatched cloud and self-hosted instances remain at risk.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.