Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

Two now-patched security holes in the n8n workflow automation platform, including two significant bugs that may lead to arbitrary command execution, have been revealed by cybersecurity researchers.

Below is a list of the vulnerabilities:

  • CVE-2026-27577 (CVSS score: 9.4) – Expression sandbox escape leading to remote code execution (RCE)
  • CVE-2026-27493 (CVSS score: 9.5) – Unauthenticated expression evaluation via n8n’s Form nodes

According to a report shared with The Hacker News by Pillar Security researcher Eilon Cohen, CVE-2026-27577 is a sandbox escape in the expression compiler: a missing case in the AST rewriter allows process to pass through untransformed, giving any authenticated expression full RCE.

CVE-2026-27493, according to the cybersecurity firm, is a “double-evaluation bug” in n8n’s Form nodes that might be exploited for expression injection by exploiting the fact that the form endpoints are public by design read more about Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials.

Get up to date on the latest cybersecurity news and enhance your knowledge of cybersecurity with our thorough coverage of the dangers, breaches, and solutions.

Leave a Reply

Your email address will not be published. Required fields are marked *