Rishi[verified]@rxeriumPoC
The tweet shares GitHub links to YAML-based vulnerability scripts for two newly disclosed n8n CVEs, enabling users to test or exploit CVE‑2026‑1470 and CVE‑2026‑0863.
ThreatSynop[verified]@ThreatSynopPatch
Two critical n8n vulnerabilities (CVE-2026-1470 and CVE-2026-0863) allow sandbox bypass and RCE, and the article provides patch/upgrade guidance for affected versions.
Security Boulevard[verified]@securityblvdDisclosure
JFrog security researchers disclosed two high‑CVSS critical vulnerabilities (CVE‑2026‑1470 and CVE‑2026‑0863) affecting n8n, but no PoC, exploit, or patch details were provided.
SOCRadar®[verified]@socradarPatch
Two sandbox escape flaws in n8n (CVE-2026-1470 and CVE-2026-0863) let authenticated users execute arbitrary code on the host; patches are available to mitigate the RCE risk.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The article announces remote code execution vulnerabilities in n8n (CVE-2026-1470, CVE-2026-0863) without providing PoC, exploit code, or patch details.
ProbablyPwned[verified]@probablypwnedDisclosure
JFrog discloses CVE-2026-1470 and CVE-2026-0863 as authenticated remote code execution vulnerabilities in its workflow automation platform. No exploitation details or patches are mentioned.
ThreatCluster[verified]@threatclusterDisclosure
The post announces critical sandbox escape vulnerabilities in the vm2 and n8n Node.js modules, exposing environments to severe risk and highlighting their high CVSS scores.
blueblue@piedpiper1616Disclosure
Jfrog Security Research reports that CVE‑2026‑1470 and CVE‑2026‑0863 allow remote code execution via a sandbox escape in n8n, confirming the vulnerability type and presenting a PoC, but no evidence of active exploitation or patches is provided.