
I recently discovered two new RCE vulnerabilities in n8n. One is a bypass for my previous finding (CVE-2025-68613), and the other is a fresh Command Injection in the Git Node. 1. The Sandbox Escape (CVE-2026-25049) I managed to bypass the fix for my original report (CVE-2025-68613) multiple times. By using Javascript quirks like Template Literals and Object Destructuring, I could escape the sandbox again. The issue has been fixed in n8n versions 1.123.17 and 2.5.2. Users should upgrade to these versions or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ 2. Git Node Command Injection (CVE-2026-25053) This one leverages the addConfig operation in the Git Node. It lacks validation, allowing an attacker to inject payloads into core.sshCommand. Leads to RCE. The issue has been fixed in n8n versions 2.5.0, and 1.123.10. Users should upgrade to this version or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-OS-command-inj/ Thanks n8n team!
Post summary
The author announces two new RCE CVEs in n8n, explains the exploitation methods and provides patch versions to remediate the issues.










