logo

Critical n8n Vulnerability CVE-2026-25049 Enables Remote Command Execution

ID: 85c68ace-7204-55dd-a027-0221e8561ece

STIX ID: report--85c68ace-7204-55dd-a027-0221e8561ece

Feed Name: The Cyber Express

Threat Score
78/100

Date Published: 2026-02-05

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical remote code execution vulnerability (CVE-2026-25049) was disclosed in the n8n workflow automation platform: authenticated users who can create or modify workflows may craft expressions that escape the expression sandbox and execute system commands on the host. The flaw bypasses earlier fixes (CVE-2025-68613), affects versions before 1.123.17 and 2.5.2, and is patched in those releases; n8n recommends immediate upgrades and temporary mitigations for environments that cannot patch immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.