PT-2026-50150 · N8N · N8N

·

CVE-2026-49444

·

Published

2026-06-16

·

Updated

2026-07-16

CVSS v3.1

8.5

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.48 n8n versions prior to 2.21.8 n8n versions prior to 2.22.4
Description An authenticated user with permissions to create or modify workflows containing a Python Code Node can escape the sandbox to achieve arbitrary code execution on the task runner container. This issue specifically affects instances where the Python Task Runner is enabled.
Recommendations Update to version 1.123.48 or later. Update to version 2.21.8 or later. Update to version 2.22.4 or later. Limit workflow creation and editing permissions to fully trusted users only. Disable the Python Code node by adding n8n-nodes-base.code to the NODES EXCLUDE environment variable. Disable the Python Task Runner entirely.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-49444
GHSA-9PQ8-M8GP-4P53

Affected Products

N8N