
🚨 CRITICAL n8n VULNERABILITY ALERT CVE-2026-25049 (CVSS 9.4) allows authenticated users to execute system commands via malicious workflows, potentially leading to full server compromise. Affected: <1.123.17, <2.5.2 Patch immediately. If you can create a workflow, you can potentially own the server. Thread reply: Additional critical n8n flaws: • CVE-2026-25053 – OS command injection • CVE-2026-25054 – Stored XSS • CVE-2026-25055 – Path traversal • CVE-2026-25056 – Arbitrary file write → RCE Restrict workflow permissions and update ASAP.
Post summary
A critical n8n vulnerability (CVE‑2026‑25049) allows authenticated users to run system commands via malicious workflows; the alert stresses immediate patching and permission restrictions.


