CVE-2026-25049Disclosure(n8n / n8n)

CRITICALCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 69 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. This issue has been patched in versions 1.123.17 and 2.5.2.

8.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-913

Priority

CRITICAL

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

DECLINING

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 4 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 132 mentions across 22 observed days

What's happening

  • Active exploitation reported across 4 signals
  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 16 signals
  • Patch or workaround mentioned in 44 signals
  • Technical details provided in 111 signals
  • Disclosure: 81 classified signals
  • General: 14 classified signals
  • Peaked 20d ago at 69 mentions (2026-02-05); latest day: 1
  • 132 total mentions across 22 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline132 mentions / 22d
017355269Mentions · 2026-02-04: 8Mentions · 2026-02-05: 69Mentions · 2026-02-06: 15Mentions · 2026-02-07: 11Mentions · 2026-02-08: 4Mentions · 2026-02-09: 3Mentions · 2026-02-11: 4Mentions · 2026-02-12: 2Mentions · 2026-02-13: 2Mentions · 2026-02-14: 1Mentions · 2026-02-17: 1Mentions · 2026-02-18: 2Mentions · 2026-02-23: 1Mentions · 2026-03-06: 1Mentions · 2026-03-11: 1Mentions · 2026-03-13: 1Mentions · 2026-03-27: 1Mentions · 2026-03-31: 1Mentions · 2026-04-30: 1Mentions · 2026-05-26: 1Mentions · 2026-09-13: 1Mentions · 2026-09-22: 1PoC Mentioned / Linked · 2026-02-04: 3PoC Mentioned / Linked · 2026-02-05: 5PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-02-07: 3PoC Mentioned / Linked · 2026-02-08: 2PoC Mentioned / Linked · 2026-02-09: 1PoC Mentioned / Linked · 2026-05-26: 1Exploit Tool / Code · 2026-02-04: 1Exploit Tool / Code · 2026-02-05: 3Exploit Tool / Code · 2026-02-07: 1Exploit Tool / Code · 2026-02-08: 2Exploit Tool / Code · 2026-02-09: 1Active Exploitation · 2026-02-04: 1Active Exploitation · 2026-02-05: 2Active Exploitation · 2026-02-13: 1Patch / Workaround · 2026-02-04: 3Patch / Workaround · 2026-02-05: 24Patch / Workaround · 2026-02-06: 6Patch / Workaround · 2026-02-07: 5Patch / Workaround · 2026-02-08: 1Patch / Workaround · 2026-02-09: 1Patch / Workaround · 2026-02-12: 1Patch / Workaround · 2026-02-13: 1Patch / Workaround · 2026-02-23: 1Patch / Workaround · 2026-03-11: 1Technical Details · 2026-02-04: 6Technical Details · 2026-02-05: 62Technical Details · 2026-02-06: 13Technical Details · 2026-02-07: 6Technical Details · 2026-02-08: 3Technical Details · 2026-02-09: 2Technical Details · 2026-02-11: 4Technical Details · 2026-02-12: 2Technical Details · 2026-02-13: 2Technical Details · 2026-02-14: 1Technical Details · 2026-02-17: 1Technical Details · 2026-02-18: 1Technical Details · 2026-03-06: 1Technical Details · 2026-03-11: 1Technical Details · 2026-03-27: 1Technical Details · 2026-03-31: 1Technical Details · 2026-04-30: 1Technical Details · 2026-05-26: 1Technical Details · 2026-09-13: 1Technical Details · 2026-09-22: 102-0402-0602-0802-1102-1302-1702-2303-1103-2704-3009-1309-22
Signal classification6 categories
Disclosure
8161.4%
Patch
2518.9%
General
1410.6%
Active Exploitation
43.0%
Exploit
43.0%
PoC
43.0%
Referenced assets105 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-048
Active Exploitation1Disclosure4Exploit1General1PoC1
2026-02-0569
Active Exploitation2Disclosure46Exploit2General3Patch16
2026-02-0615
Disclosure5General4Patch6
2026-02-0711
Disclosure6General2Patch2PoC1
2026-02-084
Disclosure2Patch1PoC1
2026-02-093
Disclosure1Exploit1General1
2026-02-114
Disclosure4
2026-02-122
Disclosure2
2026-02-132
Active Exploitation1Disclosure1
2026-02-141
Disclosure1
2026-02-171
Disclosure1
2026-02-182
Disclosure1General1
2026-02-231
General1
2026-03-061
Disclosure1
2026-03-111
Disclosure1
2026-03-131
General1
2026-03-271
Disclosure1
2026-03-311
Disclosure1
2026-04-301
Disclosure1
2026-05-261
PoC1
2026-09-131
Disclosure1
2026-09-221
Disclosure1
Full discourse20 posts
  • Rishi@rxerium
    Patch

    Yet another critical vulnerability in n8n - CVE-2026-25049 (CVSS 9.4). Vulnerability detection script here: https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-25049.yaml Patched versions are 1.123.17 / 2.5.2 as per: https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8 https://t.co/WvSEKGXVvj

    Post summary

    The post discloses a critical CVE-2026-25049 in n8n, supplies a detection script, and announces patched versions, but provides no exploit or evidence of active exploitation.

    44222279912.9K
    3.1K followersView on X
  • Fatih Çelik@fatihclk01
    Disclosure

    I recently discovered two new RCE vulnerabilities in n8n. One is a bypass for my previous finding (CVE-2025-68613), and the other is a fresh Command Injection in the Git Node. 1. The Sandbox Escape (CVE-2026-25049) I managed to bypass the fix for my original report (CVE-2025-68613) multiple times. By using Javascript quirks like Template Literals and Object Destructuring, I could escape the sandbox again. The issue has been fixed in n8n versions 1.123.17 and 2.5.2. Users should upgrade to these versions or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ 2. Git Node Command Injection (CVE-2026-25053) This one leverages the addConfig operation in the Git Node. It lacks validation, allowing an attacker to inject payloads into core.sshCommand. Leads to RCE. The issue has been fixed in n8n versions 2.5.0, and 1.123.10. Users should upgrade to this version or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-OS-command-inj/ Thanks n8n team!

    Post summary

    The author announces two new RCE vulnerabilities in n8n, provides detailed exploitation techniques and PoC links, and recommends upgrading to patched versions.

    74132108420.9K
    468 followersView on X
  • The Hacker News@TheHackersNews
    Patch

    ⚠️ Critical RCE flaw in n8n (CVE-2026-25049, CVSS 9.4) lets authenticated users execute system commands via crafted workflow expressions. Public webhooks exposed → remote trigger, credential theft, server takeover. 🔗 Exploit path, affected versions, patch details → https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html

    Post summary

    A critical remote code execution flaw (CVE‑2026‑25049) in n8n allows authenticated users to run system commands via crafted workflow expressions; patch information is available.

    75021362612.9K
    1.0M followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-25049 (CVSS 9.4): Critical n8n Flaw Enables System Command Execution via Malicious Workflows. CVE-2026-25053 (CVSS 9.4): An Operating System Command Injection Vulnerability in the Git Node. 🧐Deep Dive : https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ https://www.endorlabs.com/learn/cve-2026-25049-n8n-rce?utm_source=cybersec&utm_medium=newsfeed 📊 1.0M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22n8n%22 👇Query HUNTER : http://product.name="n8n" 📰Refer:https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8 https://github.com/n8n-io/n8n/security/advisories/GHSA-9g95-qf3f-ggrw https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html https://securityonline.info/popular-n8n-platform-hit-by-triple-threat-of-rce-flaws/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces two high‑severity CVEs in n8n, detailing command execution and injection weaknesses, and links to advisories and a deep‑dive analysis, but provides no evidence of exploitation or patches.

    214185266.9K
    25.4K followersView on X
  • Het Mehta@hetmehtaa
    General

    Breaking Down CVE-2026-25049 https://hetmehta.com/posts/n8n-type-confusion-rce/ https://t.co/zwEspWfPr7

    Post summary

    Tweet cites a blog post about CVE-2026-25049 but offers no explicit details.

    14143134.9K
    39.3K followersView on X
  • Mr. OS@ksg93rd
    PoC

    #exploit 1⃣. CVE-2025-11730: RCE via DDNS configuration in ZYXEL ATP/USG Series https://github.com/rainpwn/exploits/blob/main/zyxel/rainpwn_cve-2025-11730_ddns_rce.py ]-> PoC https://rainpwn.blog/blog/cve-2025-11730 2⃣. A Deep Dive into CVE-2026-25049: n8n RCE https://blog.securelayer7.net/cve-2026-25049 3⃣. The RCE that AMD won’t fix https://web.archive.org/web/20260205155934/https://mrbruh.com/amd 4⃣. CVE-2026-24858: Fortinet FortiCloud SSO Admin Bypass https://github.com/absholi7ly/CVE-2026-24858-FortiCloud-SSO-Authentication-Bypass 5⃣. CVE-2026-25587, CVE-2026-25641: SandboxJS Sandbox Escape https://github.com/advisories/GHSA-66h4-qj4x-38xp

    Post summary

    The tweet catalogs several CVEs, providing PoC links and brief technical details about RCE vulnerabilities, but does not report active exploitation or patch information.

    13025131.2K
    3.1K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    2026: New N8N RCE Deep Dive into CVE-2026-25049 https://blog.securelayer7.net/cve-2026-25049/

    Post summary

    The tweet points to a blog post that deep dives into the newly disclosed N8N RCE vulnerability CVE-2026-25049, but does not provide PoC, exploit code, patch information, or evidence of active exploitation.

    04015121.5K
    32.7K followersView on X
  • Het Mehta@hetmehtaa
    Disclosure

    Breaking Down CVE-2026-25049: How TypeScript Types Failed n8n's Security https://hetmehta.com/posts/n8n-type-confusion-rce/

    Post summary

    The article title and link suggest a technical analysis of CVE-2026-25049, highlighting a type‑confusion flaw in n8n’s TypeScript usage that could lead to remote code execution.

    1401291.1K
    39.7K followersView on X
  • Sandeep Kamble@SandeepL337
    PoC

    UPGRADE @n8n_io AI workflows! Dropping PoC for CVE-2026-25049 Remote Code Execution. https://youtu.be/QLrm7jx8kew

    Post summary

    The post announces that a PoC for CVE-2026-25049, a remote code execution vulnerability, has been released, with a YouTube link provided to view the demonstration.

    13092658
    1.8K followersView on X
  • Mr.Rabbit@01ra66it
    Patch

    n8nの重大脆弱性CVE-2026-25049が発覚。認証済みワークフロー編集者が悪意ある式で任意コマンド実行、サーバ完全制御に悪用の恐れ。1.123.17/2.5.2以上へ即アップデートを推奨。 #n8n #CVE202625049 #Cybersecurity https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html

    Post summary

    A newly discovered CVE-2026-25049 in n8n permits authenticated workflow editors to execute arbitrary commands, potentially granting full server control. The vendor recommends updating to v1.123.17 or v2.5.2 to mitigate the issue.

    03072518
    3.3K followersView on X
  • Fatih Çelik@fatihclk01
    Disclosure

    @TheHackersNews Thanks for sharing. Here is my blog post related CVE-2026-25049: https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/

    Post summary

    The tweet links to a blog post that mentions CVE-2026-25049, but no technical details, PoC, or exploitation information are included in the text.

    000111509
    468 followersView on X
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    ⚠️ 𝗡𝗼𝘂𝘃𝗲𝗮𝘂 𝗽𝗮𝘁𝗰𝗵 𝗻𝟴𝗻 La faille critique CVE-2026-25049 réactive une précédente vulnérabilité Retrouvez mon article à ce sujet 👇 - https://www.it-connect.fr/n8n-cve-2026-25049-execution-code-a-distance/ #n8n #infosec #nocode #cybersecurite https://t.co/zFRi1H1mVG

    Post summary

    The tweet announces a critical CVE‑2026‑25049 vulnerability that reactivates a prior flaw and points readers to an article for more information.

    05060847
    10.9K followersView on X
  • Novacybersecurity Inc. & Associates@theNovacyberqfs
    Disclosure

    ⚠️ Critical RCE flaw in n8n (CVE-2026-25049, CVSS 9.4) lets authenticated users execute system commands via crafted workflow expressions. Public webhooks exposed → remote trigger, credential theft, server takeover. 🔗 Exploit path, affected versions, patch details → https://Neurasoftdev.com

    Post summary

    A critical RCE vulnerability (CVE-2026-25049) in n8n allows authenticated users to execute system commands via crafted workflow expressions, with exposed public webhooks enabling remote triggers and potential server takeover. Patch details are provided through the supplied link.

    13043605
    1.8K followersView on X
  • Blue Team News@blueteamsec1
    Disclosure

    Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows http://dlvr.it/TRLPxk #n8n #CVE2026 #CyberSecurity #Vulnerability #Malware https://t.co/NODNWJrG1W

    Post summary

    The tweet announces the discovery of CVE‑2026‑25049, a critical n8n flaw that allows remote command execution through malicious workflows, but it does not provide proof of exploit, patch info, or evidence of active attacks.

    210341.1K
    54.9K followersView on X
  • Directoratul Național de Securitate Cibernetică@DNSC_RO
    Disclosure

    👨‍🏫CVE-2026-25049 reprezintă o vulnerabilitate critică, cu un scor CVSS de 9.4, de tip Remote Code Execution, identificată în platforma de automatizare n8n 👨‍💻Vulnerabilitatea poate fi exploatată de un potențial atacator autentificat pentru a executa comenzi neautorizate /1 #DNSC https://t.co/8TyauFryLZ

    Post summary

    A critical Remote Code Execution vulnerability (CVE-2026-25049) in n8n, rated CVSS 9.4, potentially exploitable by authenticated attackers; no PoC, patch, or active exploitation evidence is provided.

    12031219
    4.6K followersView on X
  • AZGingerHacker@AZGingerHacker
    Disclosure

    🔙 An oldie, but a goody 👀 If you work with n8n, AppSec, DevSecOps, or vulnerability research, CVE-2026-25049 is worth revisiting. A type confusion flaw → sanitizer bypass → RCE. 😬 The bigger lesson? Type safety ≠ runtime security. Great technical breakdown from Endor Labs 👇 https://api.cyfluencer.com/s/cve-2026-25049-expression-escape-vulnerability-leading-to-rce-in-n8n-29516

    Post summary

    The tweet revisits CVE‑2026‑25049, outlining a type‑confusion → sanitizer‑bypass → RCE chain and noting that type safety does not guarantee runtime security, with a link to a detailed technical breakdown from Endor Labs.

    02040167
    431 followersView on X
  • Cert-IST@cert_ist
    Disclosure

    Une vulnérabilité critique dans n8n (CVE-2026-25049) permet l’exécution de commandes système via des workflows malveillants. https://tinyurl.com/yz7yzpfc

    Post summary

    A critical vulnerability (CVE-2026-25049) in n8n permits execution of system commands through malicious workflows.

    02030337
    966 followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    2026: New N8N RCE Deep Dive into CVE-2026-25049 https://blog.securelayer7.net/cve-2026-25049/

    Post summary

    The text references a new N8N RCE vulnerability (CVE‑2026‑25049) and links to a deep‑dive blog post, but does not provide PoC, exploits, patch info, or evidence of active exploitation.

    01021431
    33.3K followersView on X
  • The Cyber Security Hub™@TheCyberSecHub
    Disclosure

    Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    A new critical vulnerability (CVE-2026-25049) in n8n permits attackers to execute arbitrary system commands through crafted workflows.

    01021491
    192.8K followersView on X
  • Blue Team News@blueteamsec1
    General

    n8n Vulnerability Analysis: CVE-2025-68613, CVE-2026-21858, CVE-2026-25049 http://dlvr.it/TRTYbK #cyber #threathunting #infosec

    Post summary

    The tweet lists three n8n CVE identifiers and a URL, but provides no further details on PoC, exploitation, patches, or technical aspects.

    10020918
    55.1K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more