CVE-2026-25049: n8n Expression Sandbox Escape Enables RCE
ID: 1a54ef90-cb2c-52c6-9b19-b0793f48c73d
STIX ID: report--1a54ef90-cb2c-52c6-9b19-b0793f48c73d
Feed Name: SOCRadar Blog
**CVE-2026-25049** is an expression sandbox escape in n8n (CVSSv4 9.4) that can allow authenticated users to execute system commands on the host; multiple exploitation paths and public technical write-ups exist, and affected versions include all n8n < 1.123.17 and 2.x from 2.0.0 up to (but not including) 2.5.2—patch to 1.123.17+/2.5.2+ (or 2.4.5+ if staying on 2.4), restrict workflow creation to trusted users, harden runtime permissions/network controls, review workflows for suspicious expressions, and rotate secrets accessed by n8n.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
