CVE-2026-25053Disclosure(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch n8n n8n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify workflows to execute arbitrary system commands or read arbitrary files on the n8n host. This issue has been patched in versions 1.123.10 and 2.5.0.

2.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 2 signals
  • Patch or workaround mentioned in 4 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • General: 2 classified signals
  • Peaked 4d ago at 3 mentions (2026-02-04); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline11 mentions / 5d
01223Mentions · 2026-02-04: 3Mentions · 2026-02-05: 3Mentions · 2026-02-06: 3Mentions · 2026-03-03: 1Mentions · 2026-03-06: 1PoC Mentioned / Linked · 2026-02-06: 1PoC Mentioned / Linked · 2026-03-06: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 2Patch / Workaround · 2026-02-06: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 3Technical Details · 2026-02-06: 2Technical Details · 2026-03-03: 1Technical Details · 2026-03-06: 102-0402-0502-0603-0303-06
Signal classification3 categories
Disclosure
763.6%
Patch
218.2%
General
218.2%
Referenced assets18 URLs
By indicator
Classification over time
DateTotalLabels
2026-02-043
Disclosure3
2026-02-053
Disclosure1Patch2
2026-02-063
Disclosure2General1
2026-03-031
General1
2026-03-061
Disclosure1
Full discourse11 posts
  • Fatih Çelik@fatihclk01
    Disclosure

    I recently discovered two new RCE vulnerabilities in n8n. One is a bypass for my previous finding (CVE-2025-68613), and the other is a fresh Command Injection in the Git Node. 1. The Sandbox Escape (CVE-2026-25049) I managed to bypass the fix for my original report (CVE-2025-68613) multiple times. By using Javascript quirks like Template Literals and Object Destructuring, I could escape the sandbox again. The issue has been fixed in n8n versions 1.123.17 and 2.5.2. Users should upgrade to these versions or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ 2. Git Node Command Injection (CVE-2026-25053) This one leverages the addConfig operation in the Git Node. It lacks validation, allowing an attacker to inject payloads into core.sshCommand. Leads to RCE. The issue has been fixed in n8n versions 2.5.0, and 1.123.10. Users should upgrade to this version or later to remediate the vulnerability. Full technical analysis: https://fatihhcelik.github.io/posts/n8n-OS-command-inj/ Thanks n8n team!

    Post summary

    The author announces two new RCE CVEs in n8n, explains the exploitation methods and provides patch versions to remediate the issues.

    74132108420.9K
    468 followersView on X
  • Hunter@HunterMapping
    Disclosure

    🚨Alert🚨 CVE-2026-25049 (CVSS 9.4): Critical n8n Flaw Enables System Command Execution via Malicious Workflows. CVE-2026-25053 (CVSS 9.4): An Operating System Command Injection Vulnerability in the Git Node. 🧐Deep Dive : https://fatihhcelik.github.io/posts/n8n-RCEs-A-Tale-of-4-Acts/ https://www.endorlabs.com/learn/cve-2026-25049-n8n-rce?utm_source=cybersec&utm_medium=newsfeed 📊 1.0M+ Services are found on the http://hunter.how yearly. 🔗Hunter Link:https://hunter.how/list?searchValue=product.name%3D%22n8n%22 👇Query HUNTER : http://product.name="n8n" 📰Refer:https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8 https://github.com/n8n-io/n8n/security/advisories/GHSA-9g95-qf3f-ggrw https://thehackernews.com/2026/02/critical-n8n-flaw-cve-2026-25049.html https://securityonline.info/popular-n8n-platform-hit-by-triple-threat-of-rce-flaws/ #hunterhow #infosec #infosecurity #OSINT #Vulnerability

    Post summary

    The post announces the critical CVE‑2026‑25049/25053 vulnerabilities in n8n, provides technical details and links to deep‑dive articles containing PoC code, but does not mention patches or active exploitation.

    214185266.9K
    25.4K followersView on X
  • The Shadowserver Foundation@Shadowserver
    General

    We are continuing to expand our n8n RCE vulnerability scanning - most recently adding CVE-2026-27495 (CVSS 9.4) tagging as well. You can track our various n8n scan results here for the most well known critical vulns: https://dashboard.shadowserver.org/statistics/combined/time-series/?date_range=30&source=http_vulnerable&source=http_vulnerable6&tag=cve-2025-68613%2B&tag=cve-2025-68668%2B&tag=cve-2026-21858%2B&tag=cve-2026-21877%2B&tag=cve-2026-25053%2B&tag=cve-2026-25056%2B&tag=cve-2026-27495%2B&dataset=unique_ips&limit=100&group_by=tag&stacking=overlap&auto_update=on Top affected: US, Germany & France. https://t.co/mEUZ9Is6bf

    Post summary

    The post announces the addition of CVE‑2026‑27495 to n8n RCE scanning, provides a dashboard link for tracking results, and lists affected regions, but does not mention exploits, patches, or active attacks.

    112032154.3K
    21.6K followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Disclosure

    🚨 Critical 0-Day in n8n (#CVE-2026-25053): How a Simple Bypass Led to Full RCE – Full Technical Breakdown + Video https://undercodetesting.com/critical-0-day-in-n8n-cve-2026-25053-how-a-simple-bypass-led-to-full-rce-full-technical-breakdown-video/ Educational Purposes!

    Post summary

    The post announces a newly discovered critical 0‑day in n8n (CVE‑2026‑25053) with a full technical breakdown and video, providing details on the RCE but no explicit active exploitation or patch information.

    0000022
    403 followersView on X
  • PurpleOps@PurpleOps_io
    Disclosure

    📢 𝐇𝐨𝐭 𝐨𝐟𝐟 𝐭𝐡𝐞 𝐩𝐫𝐞𝐬𝐬: 𝐂𝐕𝐄 𝐢𝐧𝐬𝐢𝐠𝐡𝐭𝐬! Learn how CVE-2026-25053 and related flaws enable attackers to hijack the n8n platform. Full deep-dive, impact analysis, and real-world mitigation tips. 📖 Check the detailed report → https://www.purple-ops.io/cybersecurity-threat-intelligence-blog/n8n-rce-triple-threat/ Join the discussion and tell us what you think!

    Post summary

    A new report has been released that explains how CVE‑2026‑25053 can be used to hijack the n8n platform, provides impact analysis, and offers mitigation guidance.

    0000047
    64 followersView on X
  • VulnTracker@vuln_tracker
    General

    @the_yellow_fall You now can see the full detail about CVE-2026-25053 from https://vulntracker.io/cves/CVE-2026-25053 for FREE

    Post summary

    The tweet simply points to a vulnerability tracker page for CVE‑2026‑25053, offering no additional information.

    0000044
    333 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25053 - Critical n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission to create or modify w... https://www.thehackerwire.com/vulnerability/CVE-2026-25053/ https://t.co/8QeXYHpjhS

    Post summary

    The post announces the critical CVE‑2026‑25053 affecting n8n’s Git node, noting that authenticated users can create or modify resources, with further details available in the linked article.

    0000088
    113 followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    n8n is affected by an OS Command Injection in its Git Node (CVE-2026-25053). Review your workflows for #n8n and ensure timely remediation. Patching is available. #Security #Vulnerability https://www.pulsepatch.io/posts/cve-2026-25053-n8n-os-command-injection

    Post summary

    An OS command injection vulnerability (CVE-2026-25053) affects n8n’s Git Node; patching is available and users should apply it promptly.

    0000050
    1 followersView on X
  • MR.HOLMES👾@AhammodOvi69
    Patch

    🚨 CRITICAL n8n VULNERABILITY ALERT CVE-2026-25049 (CVSS 9.4) allows authenticated users to execute system commands via malicious workflows, potentially leading to full server compromise. Affected: <1.123.17, <2.5.2 Patch immediately. If you can create a workflow, you can potentially own the server. Thread reply: Additional critical n8n flaws: • CVE-2026-25053 – OS command injection • CVE-2026-25054 – Stored XSS • CVE-2026-25055 – Path traversal • CVE-2026-25056 – Arbitrary file write → RCE Restrict workflow permissions and update ASAP.

    Post summary

    The tweet highlights a high‑severity CVE-2026-25049 that enables authenticated users to run system commands via workflows, mentions related critical flaws, and urges immediate patching and permission restrictions.

    0000097
    345 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25053 Authenticated Command Execution and File Read Vulnerability in n8n Workflow Platform https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25053

    Post summary

    A new CVE (CVE-2026-25053) is disclosed, describing an authenticated command execution and file read flaw in the n8n Workflow Platform. No proof‑of‑concept, exploit, or patch information is provided.

    0000079
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-25053 n8n is an open source workflow automation platform. Prior to versions 1.123.10 and 2.5.0, vulnerabilities in the Git node allowed authenticated users with permission … https://www.cve.org/CVERecord?id=CVE-2026-25053

    Post summary

    The text announces CVE-2026-25053 affecting n8n’s Git node, indicating that authenticated users can exploit it in versions before 1.123.10 and 2.5.0. No PoC, exploit code, or patch details are provided.

    00000189
    56.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more