Critical and High Severity n8n Sandbox Flaws Allow RCE
ID: b96327f7-a171-5a8a-969a-fe934d0b3521
STIX ID: report--b96327f7-a171-5a8a-969a-fe934d0b3521
Feed Name: Infosecurity Magazine (News)
Threat Score
Two critical sandbox-escape vulnerabilities in the n8n workflow automation platform (CVE-2026-1470 for JavaScript, CVSS 9.9; CVE-2026-0863 for Python, CVSS 8.5) allow authenticated users who can create or modify workflows to bypass JavaScript and Python sandboxing and achieve remote code execution in the main n8n process. Patches are available in specified 1.x/2.x releases; unpatched cloud and self-hosted instances remain at risk.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
