CVE-2026-27494Disclosure(n8n / n8n)

LOWCVSS 9.9 · CRITICAL

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows could use the Python Code node to escape the sandbox. The sandbox did not sufficiently restrict access to certain built-in Python objects, allowing an attacker to exfiltrate file contents or achieve RCE. On instances using internal Task Runners (default runner mode), this could result in full compromise of the n8n host. On instances using external Task Runners, the attacker might gain access to or impact other task executed on the Task Runner. Task Runners must be enabled using `N8N_RUNNERS_ENABLED=true`. The issue has been fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to this version or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Limit workflow creation and editing permissions to fully trusted users only., and/or disable the Code node by adding `n8n-nodes-base.code` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-497

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-02-26: 3Patch / Workaround · 2026-02-26: 1Technical Details · 2026-02-26: 202-26
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets4 URLs
Full discourse3 posts
  • Infoflowcloud@infoflowcloud
    Patch

    🚨*CVE* CVE-2026-27494 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27494 ----- Traducción: CVE-2026-27494 n8n… http://infoflow.cloud`

    Post summary

    CVE-2026-27494 affects n8n versions prior to 2.10.1, 2.9.3, and 1.123.22, allowing authenticated users with workflow creation/modification rights to exploit the vulnerability; patches are available in those newer releases.

    0000029
    54 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27494 n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, an authenticated user with permission to create or modify workflows… https://www.cve.org/CVERecord?id=CVE-2026-27494

    Post summary

    The text announces CVE-2026-27494 affecting n8n versions prior to 2.10.1, 2.9.3, and 1.123.22, with no additional details on exploitation or mitigation.

    00000373
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-27494 Authenticated Python Code Node Sandbox Escape in n8n Workflow Automation... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-27494 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    A new authenticated sandbox escape vulnerability (CVE-2026-27494) in n8n Workflow Automation has been disclosed, with technical details available via the provided Vulmon links.

    0000050
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more