logo

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

ID: d602fb8e-d6ab-5a57-83e8-bea4075a0fe5

STIX ID: report--d602fb8e-d6ab-5a57-83e8-bea4075a0fe5

Feed Name: The Hacker News

Threat Score
80/100

Date Published: 2026-03-11

Date Updated: 2026-04-24

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed several critical RCE-related vulnerabilities in the n8n workflow automation platform (including CVE-2026-27577 and CVE-2026-27493) that allow expression sandbox escape and unauthenticated expression evaluation via public form endpoints; chained exploitation can lead to full remote code execution and decryption of stored credentials. n8n has released fixes in versions 2.10.1, 2.9.3, and 1.123.22 and provided mitigation guidance (restricting workflow permissions, disabling Form/Merge nodes, using external runners) while noting no public reports of in-the-wild exploitation to date.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.