Tag: Malicious Workflows

Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
News

Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows

The n8n workflow automation software has been found to have a new, serious security flaw that, if properly exploited, might cause arbitrary system commands to be executed. The vulnerability, identified as CVE-2026-25049 (CVSS score: 9.4), is caused by insufficient sanitization, which circumvents the security measures implemented to fix CVE-2025-68613 (CVSS score: 9.9), another serious weakness that was fixed by n8n in December 2025. Following CVE-2025-68613, more attacks in n8n's expression evaluation have been found and fixed, according to an advisory published on Wednesday by n8n's maintainers. Workflow parameters could contain forged expressions that an authenticated user with the ability to create or edit workflows could misuse to cause the host running n8n read more about Cr...