Exploitation observed; activity peaked at 3 mentions and remains active
Immediate actions
Patch n8n n8n systems immediately
Assume compromise if assets are exposed
Recommended action window: Immediate (within 24h)
NVD description
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.
“n8n” platformasında boşluq (CVE-2026-25115) aşkar olunub.
#ETX#MilliCERT#cybersecurity#kibertəhlükəsizlik #xəbərdarlıq https://t.co/WbZVBJplz5
Post summary
A CVE‑2026‑25115 vulnerability has been discovered in the n8n platform, with no additional details about exploitation, patches, or technical specifics.
🔴 CVE-2026-25115 - Critical
n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environme...
https://www.thehackerwire.com/vulnerability/CVE-2026-25115/ https://t.co/GsPhX1QYRv
Post summary
The tweet announces a critical CVE-2026-25115 in n8n, noting that authenticated users can escape the Python sandbox, but provides no PoC, exploit details, patch, or evidence of active exploitation.
Today's Top Cybersecurity News – February 05, 2026
1. Critical Metro4Shell RCE Vulnerability Actively Exploited in React Native CLI
The Metro4Shell vulnerability (CVE-2025-11953) in the React Native Metro Development Server is being actively exploited by threat actors to execute arbitrary code remotely. This flaw allows attackers to deliver malicious payloads targeting developer systems on Windows and Linux, posing a significant risk to development environments.
Sources: Bleepingcomputer, Crowdstrike, Cvefeed, Darkreading, Feedburner, Gbhackers, Infosecurity-Magazine, Krebsonsecurity, Securityaffairs, Securityweek
https://thehackernews.com/2026/02/hackers-exploit-metro4shell-rce-flaw-in.html
2. CVE-2026-1341: Critical Missing Authentication in Avation Light Engine Pro
Avation Light Engine Pro's configuration and control interface lacks any authentication or access control, allowing unauthorized users to potentially manipulate critical settings. This vulnerability poses a severe risk of unauthorized access and control over affected systems.
Sources: Cvefeed, Gbhackers
https://cvefeed.io/vuln/detail/CVE-2026-1341
3. Multiple Critical Vulnerabilities in n8n Workflow Automation Platform Allow RCE and Data Exposure
Several severe vulnerabilities have been identified in the n8n open source workflow automation platform, including sandbox escapes, arbitrary file write and read, OS command injection, and stored XSS. These flaws allow authenticated users with workflow modification permissions to execute remote code, read sensitive files, and perform cross-site scripting attacks, potentially leading to full system compromise. Patches addressing these issues have been released in recent versions.
Sources: Bleepingcomputer, Cvefeed, Feedburner, Infosecurity-Magazine
https://cvefeed.io/vuln/detail/CVE-2026-25115
4. Multiple Critical Vulnerabilities Disclosed in Wireless Access Points Including ELECOM and Hikvision
Several critical vulnerabilities have been disclosed affecting wireless access points from ELECOM, Hikvision, and WRC models. These include a stack-based buffer overflow, authenticated command execution, and OS command injection, potentially allowing arbitrary code or command execution by attackers. Immediate mitigation and patching are recommended to prevent exploitation.
Sources: Cvefeed, Gbhackers
https://cvefeed.io/vuln/detail/CVE-2026-24465
5. Critical XXE Vulnerability in Apache Syncope Console Enables Session Hijacking
A critical XML External Entity (XXE) vulnerability (CVE-2026-23795) in Apache Syncope's Console component allows authenticated administrators to execute attacks that can extract sensitive data and hijack active user sessions. This flaw affects multiple versions and poses significant risks to identity and access management systems.
Sources: Cvefeed, Gbhackers
https://gbhackers.com/apache-syncope-vulnerability/
Stay sharp. Stay secure.
#NerdieNews#InfoSec#CyberSecurity#TechNews#DataSecurity#CyberThreats
Post summary
The post reports several critical CVEs, confirming that Metro4Shell is actively exploited, and provides technical details and patch information.
CVE-2026-25115: Snake in the Grass: Breaking n8n's Python Sandbox via Symlink Voodoo
A critical sandbox escape vulnerability in the n8n workflow automation platform allows authenticated users to execute arbitrary code on the host system. The flaw resi...
https://cvereports.com/reports/CVE-2026-25115
Post summary
The report announces a critical sandbox escape vulnerability (CVE-2026-25115) in n8n that lets authenticated users run arbitrary code on the host system.
CVE-2026-25115 n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Pyt… https://www.cve.org/CVERecord?id=CVE-2026-25115
Post summary
The CVE impacts n8n’s Python Code node; upgrading to version 2.4.8 mitigates the vulnerability.
n8n is affected by a Python sandbox escape (CVE-2026-25115). Upgrade to v2.4.8 to address this #n8n#security#vulnerability. https://www.pulsepatch.io/posts/cve-2026-25115-n8n-python-sandbox-escape
Post summary
The tweet announces that n8n is vulnerable to CVE-2026-25115, a Python sandbox escape, and advises upgrading to version 2.4.8 to remediate.