Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
ID: d5c84953-0888-519f-807b-d5932f6689e5
STIX ID: report--d5c84953-0888-519f-807b-d5932f6689e5
Feed Name: The Hacker News
A critical remote code execution vulnerability (CVE-2026-25049, CVSS 9.4) and several related high-severity flaws were disclosed in the n8n workflow automation platform, allowing authenticated users who can create or modify workflows (and especially those who expose public webhooks) to bypass the expression sandbox and execute arbitrary system commands; affected versions include <1.123.17 and <2.5.2 with fixes in 1.123.17/2.5.2. Multiple security researchers contributed to the findings, n8n has released patches and advisories for this and eleven other vulnerabilities, and recommended mitigations include immediate updates, restricting workflow creation permissions, and deploying n8n in a hardened environment.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
