logo

Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows

ID: d5c84953-0888-519f-807b-d5932f6689e5

STIX ID: report--d5c84953-0888-519f-807b-d5932f6689e5

Feed Name: The Hacker News

Threat Score
78/100

Date Published: 2026-02-05

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

A critical remote code execution vulnerability (CVE-2026-25049, CVSS 9.4) and several related high-severity flaws were disclosed in the n8n workflow automation platform, allowing authenticated users who can create or modify workflows (and especially those who expose public webhooks) to bypass the expression sandbox and execute arbitrary system commands; affected versions include <1.123.17 and <2.5.2 with fixes in 1.123.17/2.5.2. Multiple security researchers contributed to the findings, n8n has released patches and advisories for this and eleven other vulnerabilities, and recommended mitigations include immediate updates, restricting workflow creation permissions, and deploying n8n in a hardened environment.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.