PT-2026-22035 · N8N · N8N

·

CVE-2026-27577

·

Published

2025-12-22

·

Updated

2026-07-28

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 2.10.1 n8n versions prior to 2.9.3 n8n versions prior to 1.123.22
Description An authenticated user with permissions to create or modify workflows can abuse crafted expressions within workflow parameters to trigger unintended system command execution on the host running the platform. This occurs because expressions supplied during workflow configuration may be evaluated in an execution context that is not sufficiently isolated from the underlying runtime, allowing for a sandbox escape. Successful exploitation can lead to a full compromise of the instance, including unauthorized access to sensitive data and execution of system-level operations with the privileges of the n8n process.
Recommendations Update to version 2.10.1 or later. Update to version 2.9.3 or later. Update to version 1.123.22 or later. Limit workflow creation and editing permissions to fully trusted users only. Deploy the software in a hardened environment with restricted operating system privileges and network access.

Exploit

Fix

RCE

Code Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-27577
GHSA-V98V-FF95-F3CP
GHSA-VPCF-GVG4-6QWR

Affected Products

N8N