Fatih Çelik[verified]@fatihclk01Disclosure
A new RCE vulnerability (CVE-2026-27498) in n8n has been discovered, and the author plans to share a blog post with details.
Fatih Çelik[verified]@fatihclk01PoC
The blog post discloses CVE-2026-27498 in n8n, provides PoC code and technical details, and references the vendor patch, but does not report active exploitation.
Selwyn | Automating Solopreneur Workflows[verified]@algonovalabsGeneral
The post references CVE-2026-27498 but only offers general security recommendations, lacking specific vulnerability details or exploitation evidence.
OffSeq | Adversary Tactics for Cyber Resilience[verified]@offseqPatch
A critical code injection vulnerability (CVE‑2026‑27498) in n8n‑io n8n allows authenticated users to gain shell access; patching to 2.2.0 / 1.123.8 is urgently recommended.
Jintao Zhang 张晋涛@zhangjintao9020Patch
The post announces four high‑severity CVEs affecting n8n (remote command execution) and urges users to upgrade to the latest version for remediation.
Vulmon Vulnerability Feed@VulmonFeedsDisclosure
A new authenticated remote code execution vulnerability (CVE-2026-27498) has been identified in the n8n Workflow Automation Platform.
PulsePatch.io@pulsepatchioPatch
CVE-2026-27498 allows arbitrary command execution in n8n through file write and Git operations; updating to version 1.123.8 mitigates the vulnerability.
Autumn Good@autumn_good_35Disclosure
The advisory reveals that authenticated users in n8n can chain workflow nodes to perform arbitrary command execution via file write and git operations, enabling remote code execution.