CVE-2026-25115Disclosure(n8n / n8n)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 3 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-693

Priority

MEDIUM

Exploitation

ACTIVE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 1 classified signals
  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • Peaked 2d ago at 3 mentions (2026-02-04); latest day: 1
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline7 mentions / 3d
01223Mentions · 2026-02-04: 3Mentions · 2026-02-05: 3Mentions · 2026-02-11: 1Active Exploitation · 2026-02-05: 1Patch / Workaround · 2026-02-04: 1Patch / Workaround · 2026-02-05: 2Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 302-0402-0502-11
Signal classification3 categories
Disclosure
457.1%
Patch
228.6%
Active Exploitation
114.3%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-02-043
Disclosure2Patch1
2026-02-053
Active Exploitation1Disclosure1Patch1
2026-02-111
Disclosure1
Full discourse7 posts
  • CERT Azerbaijan@CERTAzerbaijan
    Disclosure

    “n8n” platformasında boşluq (CVE-2026-25115) aşkar olunub. #ETX #MilliCERT #cybersecurity #kibertəhlükəsizlik #xəbərdarlıq https://t.co/WbZVBJplz5

    Post summary

    A CVE‑2026‑25115 vulnerability has been discovered in the n8n platform, with no additional details about exploitation, patches, or technical specifics.

    0001079
    134 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🔴 CVE-2026-25115 - Critical n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environme... https://www.thehackerwire.com/vulnerability/CVE-2026-25115/ https://t.co/GsPhX1QYRv

    Post summary

    The tweet announces a critical CVE-2026-25115 in n8n, noting that authenticated users can escape the Python sandbox, but provides no PoC, exploit details, patch, or evidence of active exploitation.

    0001078
    113 followersView on X
  • NerdieNews@NewsNerdie
    Active Exploitation

    Today's Top Cybersecurity News – February 05, 2026 1. Critical Metro4Shell RCE Vulnerability Actively Exploited in React Native CLI The Metro4Shell vulnerability (CVE-2025-11953) in the React Native Metro Development Server is being actively exploited by threat actors to execute arbitrary code remotely. This flaw allows attackers to deliver malicious payloads targeting developer systems on Windows and Linux, posing a significant risk to development environments. Sources: Bleepingcomputer, Crowdstrike, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Krebsonsecurity, Securityaffairs, Securityweek https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html 2. CVE-2026-1341: Critical Missing Authentication in Avation Light Engine Pro Avation Light Engine Pro's configuration and control interface lacks any authentication or access control, allowing unauthorized users to potentially manipulate critical settings. This vulnerability poses a severe risk of unauthorized access and control over affected systems. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-1341 3. Multiple Critical Vulnerabilities in n8n Workflow Automation Platform Allow RCE and Data Exposure Several severe vulnerabilities have been identified in the n8n open source workflow automation platform, including sandbox escapes, arbitrary file write and read, OS command injection, and stored XSS. These flaws allow authenticated users with workflow modification permissions to execute remote code, read sensitive files, and perform cross-site scripting attacks, potentially leading to full system compromise. Patches addressing these issues have been released in recent versions. Sources: Bleepingcomputer, Cvefeed, Feedburner, Infosecurity-Magazine https://cvefeed.io/vuln/detail/CVE-2026-25115 4. Multiple Critical Vulnerabilities Disclosed in Wireless Access Points Including ELECOM and Hikvision Several critical vulnerabilities have been disclosed affecting wireless access points from ELECOM, Hikvision, and WRC models. These include a stack-based buffer overflow, authenticated command execution, and OS command injection, potentially allowing arbitrary code or command execution by attackers. Immediate mitigation and patching are recommended to prevent exploitation. Sources: Cvefeed, Gbhackers https://cvefeed.io/vuln/detail/CVE-2026-24465 5. Critical XXE Vulnerability in Apache Syncope Console Enables Session Hijacking A critical XML External Entity (XXE) vulnerability (CVE-2026-23795) in Apache Syncope's Console component allows authenticated administrators to execute attacks that can extract sensitive data and hijack active user sessions. This flaw affects multiple versions and poses significant risks to identity and access management systems. Sources: Cvefeed, Gbhackers https://gbhackers.com/apache-syncope-vulnerability/ Stay sharp. Stay secure. #NerdieNews #InfoSec #CyberSecurity #TechNews #DataSecurity #CyberThreats

    Post summary

    The post reports several critical CVEs, confirming that Metro4Shell is actively exploited, and provides technical details and patch information.

    0001068
    54 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-25115: Snake in the Grass: Breaking n8n's Python Sandbox via Symlink Voodoo A critical sandbox escape vulnerability in the n8n workflow automation platform allows authenticated users to execute arbitrary code on the host system. The flaw resi... https://cvereports.com/reports/CVE-2026-25115

    Post summary

    The report announces a critical sandbox escape vulnerability (CVE-2026-25115) in n8n that lets authenticated users run arbitrary code on the host system.

    0001055
    27 followersView on X
  • CVE@CVEnew
    Patch

    CVE-2026-25115 n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Pyt… https://www.cve.org/CVERecord?id=CVE-2026-25115

    Post summary

    The CVE impacts n8n’s Python Code node; upgrading to version 2.4.8 mitigates the vulnerability.

    00010182
    56.5K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    n8n is affected by a Python sandbox escape (CVE-2026-25115). Upgrade to v2.4.8 to address this #n8n #security #vulnerability. https://www.pulsepatch.io/posts/cve-2026-25115-n8n-python-sandbox-escape

    Post summary

    The tweet announces that n8n is vulnerable to CVE-2026-25115, a Python sandbox escape, and advises upgrading to version 2.4.8 to remediate.

    0000064
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-25115 Python Sandbox Escape Vulnerability in n8n Workflow Autom... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-25115 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE‑2026‑25115, indicating a Python sandbox escape in n8n, but offers no PoC, exploit, or patch details.

    0000056
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more