OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
The tweet alerts users to a critical code injection vulnerability in n8n-io n8n that allows authenticated users to execute code via the Merge node, and urges an immediate upgrade to specific patched versions.
Jintao Zhang 张晋涛@zhangjintao9020Patch
The post reports four high‑severity n8n vulnerabilities (CVE‑2026‑27495, ‑27497, ‑27498, ‑27577) that allow remote command execution, and urges users to update to the latest version.
CCB Alert@CCBalertPatch
Multiple critical CVEs (CVE‑2026‑27497, 27495, 27577) in n8n with CVSS 9.4 can fully compromise a host; users are urged to patch immediately.
Gray Hats@the_yellow_fallPatch
n8n has released patches for three critical CVEs that enable remote code execution via Merge nodes and sandboxes; users are urged to update immediately.
PulsePatch.io@pulsepatchioPatch
The post discloses an RCE vulnerability (CVE‑2026‑27497) in n8n’s Merge Node and advises upgrading to 1.123.22, providing a link to further details.
Autumn Good@autumn_good_35Disclosure
Authenticated users can exploit the Merge node’s SQL query mode in n8n to execute arbitrary code and write files, exposing a remote code execution vulnerability (CVE-2026-27497).
Infoflowcloud@infoflowcloudPatch
CVE-2026-27497 affects n8n, allowing authenticated users to create or modify workflows before versions 2.10.1, 2.9.3, and 1.123.22; patches are available in those releases.
CVE@CVEnewPatch
The CVE-2026-27497 vulnerability in n8n affects versions prior to 2.10.1, 2.9.3, and 1.123.22, and patches are available in those newer releases.