logo

CVE-2026-1470 & CVE-2026-0863: Severe Sandbox Escape Vulnerabilities Expose n8n Instances to RCE

ID: 02911260-f728-5f66-8b5a-749125d17011

STIX ID: report--02911260-f728-5f66-8b5a-749125d17011

Feed Name: SOCRadar Blog

Threat Score
78/100

Date Published: 2026-01-29

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

Researchers disclosed two high-impact sandbox-escape vulnerabilities in the n8n automation platform—CVE-2026-1470 (JS, CVSS 9.9) and CVE-2026-0863 (Python, CVSS 8.5)—that let authenticated users who can create or edit workflows bypass AST-based sandboxes to execute arbitrary code on the host; affected versions are identified and patches are available, with recommended mitigations including immediate patching, avoiding internal Python execution, restricting workflow editing privileges, and continuous monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.