logo

CVE-2026-25049: n8n Expression Sandbox Escape Enables RCE

ID: 1a54ef90-cb2c-52c6-9b19-b0793f48c73d

STIX ID: report--1a54ef90-cb2c-52c6-9b19-b0793f48c73d

Feed Name: SOCRadar Blog

Threat Score
80/100

Date Published: 2026-02-05

Date Updated: 2026-04-30

Author: Ameer Owda

...
...

**CVE-2026-25049** is an expression sandbox escape in n8n (CVSSv4 9.4) that can allow authenticated users to execute system commands on the host; multiple exploitation paths and public technical write-ups exist, and affected versions include all n8n < 1.123.17 and 2.x from 2.0.0 up to (but not including) 2.5.2—patch to 1.123.17+/2.5.2+ (or 2.4.5+ if staying on 2.4), restrict workflow creation to trusted users, harden runtime permissions/network controls, review workflows for suspicious expressions, and rotate secrets accessed by n8n.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.