CVE-2026-27577Patch(n8n / n8n)

MEDIUMCVSS 9.9 · CRITICAL

Exploitation observed; activity peaked at 7 mentions and remains active

Immediate actions

  • Patch n8n n8n systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.10.1, 2.9.3, and 1.123.22, additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613. An authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. The issues have been fixed in n8n versions 2.10.1, 2.9.3, and 1.123.22. Users should upgrade to one of these versions or later to remediate all known vulnerabilities. If upgrading is not immediately possible, administrators should consider the following temporary mitigations. Limit workflow creation and editing permissions to fully trusted users only, and/or deploy n8n in a hardened environment with restricted operating system privileges and network access to reduce the impact of potential exploitation. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

5.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Active exploitation appears in 2 classified signals
  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 27 mentions across 13 observed days

What's happening

  • Active exploitation reported across 2 signals
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 18 signals
  • Technical details provided in 25 signals
  • Disclosure: 9 classified signals
  • General: 3 classified signals
  • Peaked 12d ago at 7 mentions (2026-02-26); latest day: 2
  • 27 total mentions across 13 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline27 mentions / 13d
02457Mentions · 2026-02-26: 7Mentions · 2026-02-27: 1Mentions · 2026-03-10: 1Mentions · 2026-03-11: 3Mentions · 2026-03-12: 3Mentions · 2026-03-13: 1Mentions · 2026-03-20: 2Mentions · 2026-03-27: 1Mentions · 2026-04-15: 1Mentions · 2026-04-24: 1Mentions · 2026-07-27: 3Mentions · 2026-07-28: 1Mentions · 2026-07-29: 2PoC Mentioned / Linked · 2026-07-27: 1Active Exploitation · 2026-03-12: 1Active Exploitation · 2026-07-27: 1Patch / Workaround · 2026-02-26: 3Patch / Workaround · 2026-02-27: 1Patch / Workaround · 2026-03-10: 1Patch / Workaround · 2026-03-11: 3Patch / Workaround · 2026-03-12: 3Patch / Workaround · 2026-03-20: 1Patch / Workaround · 2026-04-15: 1Patch / Workaround · 2026-04-24: 1Patch / Workaround · 2026-07-27: 1Patch / Workaround · 2026-07-28: 1Patch / Workaround · 2026-07-29: 2Technical Details · 2026-02-26: 6Technical Details · 2026-02-27: 1Technical Details · 2026-03-10: 1Technical Details · 2026-03-11: 3Technical Details · 2026-03-12: 3Technical Details · 2026-03-13: 1Technical Details · 2026-03-20: 2Technical Details · 2026-03-27: 1Technical Details · 2026-04-15: 1Technical Details · 2026-04-24: 1Technical Details · 2026-07-27: 2Technical Details · 2026-07-28: 1Technical Details · 2026-07-29: 202-2602-2703-1003-1103-1203-1303-2003-2704-1504-2407-2707-2807-29
Signal classification4 categories
Patch
1348.1%
Disclosure
933.3%
General
311.1%
Active Exploitation
27.4%
Referenced assets19 URLs
Classification over time
DateTotalLabels
2026-02-267
Disclosure4General1Patch2
2026-02-271
Patch1
2026-03-101
Patch1
2026-03-113
Disclosure1Patch2
2026-03-123
Active Exploitation1Patch2
2026-03-131
Disclosure1
2026-03-202
Disclosure2
2026-03-271
General1
2026-04-151
Patch1
2026-04-241
Disclosure1
2026-07-273
Active Exploitation1General1Patch1
2026-07-281
Patch1
2026-07-292
Patch2
Full discourse20 posts
  • Wazuh@wazuh
    Patch

    n8n is affected by CVE-2026-27577, a critical code injection flaw that may allow authenticated users with workflow permissions to execute system commands. Update to 1.123.22, 2.9.3, or 2.10.1 immediately. Read more: https://ow.ly/oqr350YrJJY https://t.co/YpOIO3jqcO

    Post summary

    The tweet announces that n8n is affected by CVE-2026-27577, a critical code injection flaw, and urges users to update to the specified versions immediately.

    090202700
    7.9K followersView on X
  • Security Joes@SecurityJoes
    General

    Full blog: https://securityjoes.com/blog/breaking-the-sandbox-again-bypassing-n8n-s-cve-2026-27577-patch

    Post summary

    The provided text only gives a link to a blog post about CVE‑2026‑27577, without any detailed information on exploitation, patches, or technical specifics.

    040103951
    2.6K followersView on X
  • Security Joes@SecurityJoes
    Patch

    It took the @n8n_io team less than a week to patch the bypass our research team found for CVE-2026-27577. The issue allowed an authenticated attacker to escape the sandbox and achieve Remote Code Execution on the underlying n8n host. Great collaboration with n8n! https://t.co/IQdNQeXcnU

    Post summary

    n8n released a patch for CVE-2026-27577, which could allow authenticated attackers to escape the sandbox and execute remote code; no active exploitation or PoC was reported.

    121721.5K
    2.6K followersView on X
  • Jintao Zhang 张晋涛@zhangjintao9020
    Disclosure

    最近 n8n 爆出来了 4 个高危漏洞 CVE-2026-27495/CVE-2026-27497/CVE-2026-27498/CVE-2026-27577 一个 9.0,三个 9.4。 基本的影响都是允许执行远程命令。 这个事情倒是也不能说完全怪 n8n,大多数这种场景下的工具都会有类似的情况,各种 sandbox 逃逸,大家如果有自己部署的 n8n 记得升级到最新版

    Post summary

    The post announces four high‑severity CVEs in n8n that allow remote command execution, stressing the importance of upgrading to the latest version.

    011724.9K
    12.5K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Patch

    🚨 Upozorňujeme na kritické zranitelnosti v n8n, CVE-2026-27493 a CVE-2026-27577. CVE-2026-27493: Zranitelnost v n8n Form nodes umožňuje neautentizovanému útočníkovi bez jakékoliv interakce uživatele provést vzdálené spuštění libovolného kódu. Chyba spočívá v mechanismu dvojité evaluace výrazů: pokud vícekrokový formulář zobrazuje uživatelský vstup zpět odesílateli přes HTML renderovací krok, vstup je dvakrát vyhodnocen jako výraz. Útočník tak může vložit škodlivý výraz, který vede k vykonání shell příkazů na serveru. Může tak dojít k plnému převzetí systému a potenciálnímu úniku citlivých přihlašovacích údajů. Útok je možný bez autentizace a je spustitelný přes veřejné endpointy vícekrokových formulářů. CVE-2026-27577: Zranitelnost v kompilátoru výrazů n8n umožňuje autentizovanému útočníkovi obejít sandbox pomocí chybějícího přepisování některých struktur v AST, například SpreadElement. Kvůli této chybě nejsou určité výrazy správně transformovány, což vede k úniku ze sandboxu a přímému přístupu k prostředí Node.js. Útočník tak může interagovat se systémovými procesy a získat rozšířená oprávnění. 📌Doporučujeme n8n aktualizovat na verzi 2.10.1, 2.9.3, 1.123.22, případně vyšší.

    Post summary

    The text announces critical vulnerabilities in n8n (CVE‑2026‑27493 and CVE‑2026‑27577) that enable remote code execution and sandbox escape, and it urges users to upgrade to the patched versions mentioned.

    03060785
    4.2K followersView on X
  • striga@striga_ai
    Disclosure

    First public finding from Striga. Two vulnerabilities in n8n's expression engine chained into remote code execution. 230K+ active users, nearly 200M Docker pulls. CVE-2026-27577, CVSSv4.0 9.4 Critical. https://www.striga.ai/research/breaking-n8n-expression-sandbox

    Post summary

    Striga’s research discloses a critical remote code execution vulnerability (CVE‑2026‑27577) in n8n’s expression engine, affecting over 230K users and 200M Docker pulls.

    03041148
    6 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Multiple Critical Vulnerabilities in #n8n. CVE-2026-27497 CVE-2026-27577 CVE-2026-27495 CVSS: 9.4. These vulnerabilities can lead to a full compromised host https://ccb.belgium.be/advisories/warning-multiple-critical-vulnerabilities-n8n-patch-immediately #Patch #Patch #Patch

    Post summary

    The advisory highlights several high‑severity CVEs affecting n8n, urging immediate patching to prevent potential full‑host compromise.

    02210707
    7.2K followersView on X
  • Misbar | مسبار@MisbarSec
    Patch

    📌 تم اكتشاف ثغرة في نظام n8n يسمح للمحررين بتنفيذ أوامر نظام التشغيل على الخادم 🛡️ الفئة: ثغرة 📝 الملخص: تم العثور على ثغرة في نظام n8n تتيح للمحررين ذوي الصلاحيات تنفيذ أوامر نظام التشغيل على الخادم الذي يعمل عليه. تم اكتشاف هذه الثغرة أثناء اختبار تصحيح CVE-2026-27577. تعتبر هذه الثغرة خطيرة وتؤثر على الإصدارات <2.31.5 و >=2.32.0,<2.32.1. تم إصلاح هذه الثغرة في الإصدارات 2.31.5 و 2.32.1. يُنصح بـتحديث النظام إلى الإصدار الأخير لمنع حدوث أي اختراقات. 🗓️ تاريخ النشر: 27/07/2026 🔗 للمزيد: https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

    Post summary

    The post highlights a newly disclosed CVE‑2026‑27577 in n8n that permits privileged users to run system commands, notes the available patches for versions 2.31.5 and 2.32.1, and urges updating to the latest release, with no indication of active exploitation or a PoC.

    00040490
    423 followersView on X
  • Jim Nitterauer 🇺🇸@JNitterauer
    Patch

    n8n patched a sandbox escape (CVSS 8.7) letting a workflow editor run OS commands as the n8n process, one arrow function bypasses the fix for CVE-2026-27577. Update to 2.31.5 / 2.32.1. Automation = privileged infra. https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html #cybersecurity

    Post summary

    n8n has released patches (2.31.5 / 2.32.1) for CVE-2026-27577, a sandbox escape that lets workflow editors run OS commands, and notes a bypass via an arrow function; the update addresses the issue.

    10020220
    8.5K followersView on X
  • Autumn Good@autumn_good_35
    Disclosure

    The Unauthenticated Endpoint: Form Node Double-Evaluation (CVE-2026-27493) The Sandbox Escape: SpreadElement Bypass (CVE-2026-27577) Zero Click Unauthenticated RCE in n8n: A Contact Form That Executes Shell Commands https://www.pillar.security/blog/zero-click-unauthenticated-rce-in-n8n-a-contact-form-that-executes-shell-commands

    Post summary

    The text announces new CVEs by headline, referencing a zero‑click RCE in n8n, but provides no PoC, exploit code, or patch information.

    001101.1K
    6.7K followersView on X
  • Modat@modat_magnify
    Active Exploitation

    CVE-2025-68613 / CVE-2026-27577 / CVE-2026-27493  ⚠️ n8n Workflow Automation – Actively Exploited RCE (CISA KEV)  CISA has added CVE-2025-68613 (CVSS 10.0) to its KEV catalogue following evidence of active exploitation impacting n8n.  The flaw is an improper control of dynamically managed code resources vulnerability in n8n’s workflow expression evaluation system that allows authenticated attackers to execute arbitrary code with the privileges of the n8n process.  This follows CVE-2026-27577 (CVSS 9.4), an expression sandbox escape enabling authenticated RCE, and CVE-2026-27493 (CVSS 9.5), an unauthenticated expression injection flaw in Form nodes. When chained, attackers may execute commands and extract stored credentials.  Fixed in 1.120.4 / 1.121.1 / 1.122.0 (CVE-2025-68613) and 2.10.1 / 2.9.3 / 1.123.22 (CVE-2026-27577 and -27493). Patch immediately.  Modat Magnify Query:  web.title~"http://n8n.io - Workflow Automation" tag!=honeypot  The platform:  https://magnify.modat.io/  #threatintel #vulnerability #CVE202568613 #CVE202627577 #CVE202627493 #n8n #RCE #CISA #KEV #infosec #ModatMagnify

    Post summary

    The announcement highlights that CVE-2025-68613 and related CVEs are actively exploited in n8n, with CISA confirming active attacks and urging immediate patching.

    10010239
    291 followersView on X
  • Aviatrix Threat Research Center@aviatrixtrc
    Active Exploitation

    TRC analysis shows authenticated n8n users exploited crafted workflow expressions to execute system commands, bypassing sandbox protections entirely. The vulnerability (CVE-2026-27577) enabled attackers to pivot from workflow permissions to full host control. Runtime segmentation helps contain such post-compromise lateral movement. #ZeroTrust 🔗 Full TRC analysis: https://aviatrix.ai/threat-research-center/n8n-sandbox-escape-ghsa-gv7g-jm28-cr3m

    Post summary

    TRC analysis confirms that CVE-2026-27577 (an n8n sandbox escape) was actively exploited by authenticated users to gain full host control via crafted workflow expressions. No patch or workaround is mentioned, but technical details and a link to the full analysis are provided.

    1000059
    1.9K followersView on X
  • Pillar Security@Pillar_sec
    Disclosure

    Pillar's research team found a zero-click, unauthenticated RCE in @n8n_io (CVE-2026-27493, CVSS 9.5 Critical & CVE-2026-27577 CVSS 9.4 Critical). No account. No authentication. A browser and a contact form is all it takes to execute shell commands on the server and decrypt every credential stored in the platform. We scanned for publicly accessible n8n form endpoints and found over 50,000 potentially vulnerable forms exposed to the internet. We worked with the n8n team to fix it. If you're self-hosting, update to the latest version now. Read more: https://www.pillar.security/blog/zero-click-unauthenticated-rce-in-n8n-a-contact-form-that-executes-shell-commands

    Post summary

    Pillar’s research uncovered a critical zero‑click, unauthenticated RCE in n8n that occurs through a contact form, exposing thousands of vulnerable deployments; the vendor has issued a fix and users are urged to update.

    0001075
    151 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    n8n の脆弱性 CVE-2026-27577/27493 が FIX:サンドボックス・エスケープによる乗っ取りの可能性 https://iototsecnews.jp/2026/03/13/critical-zero-click-flaw-in-n8n-allows-full-server-compromise/ AI エージェント/ワークフローを支えるオープンソース・プラットフォーム n8n に、サーバの完全な乗っ取りを許す 2 件の深刻な脆弱性が発見されました。n8n が多様な外部サービス (AWS/GitHub/Slack など) の認証情報の保管庫として機能しているため、サンドボックスの突破により、接続されている全システムへの鍵が流出するという、危険な状況にあります。 脆弱性 CVE-2026-27577 (CVSS v4.0:9.4) は、ワークフロー内で使用される式のコンパイル処理における不備に起因します。認証済みユーザーが、悪意の式を挿入することで、安全に分離されているはずの実行環境が回避され、サーバ上での任意の OS コマンド実行が可能になります。 さらに深刻なのが、脆弱性 CVE-2026-27493 (CVSS v4.0:9.5) です。この脆弱性は、n8nの Formノードにおける入力値の二重評価という設計ミスに起因します。この攻撃では、認証が不要であるため、アカウントを持っていない攻撃者であっても、公開されている問い合わせフォームなどの入力欄に特定のコードを書き込み、サーバを遠隔操作できてしまいます。ご利用のチームは、ご注意ください。 #CVE202627493 #CVE202627577 #n8n #Vulnerability

    Post summary

    The article announces the discovery and subsequent fix of two critical vulnerabilities in the n8n platform, detailing their technical aspects and severity scores.

    01000184
    484 followersView on X
  • Eilon Cohen@NoShitOasis
    Disclosure

    Welcome my new latest findings at @Pillar_sec: - Unauthenticated Expression Evaluation via Form Node in n8n (CVE-2026-27493, CVSS v4 9.5) - Expression Sandbox Escape Leading to RCE in n8n (CVE-2026-27577, CVSS v4 9.4) Highly recommended to update n8n to patched versions.

    Post summary

    The post announces two high‑severity CVEs (CVE‑2026‑27493 and CVE‑2026‑27577) affecting n8n, providing technical details and urging users to apply patches.

    1000070
    178 followersView on X
  • OffSeq | Adversary Tactics for Cyber Resilience@offseq
    Patch

    🚨 CRITICAL: n8n workflow automation hit by CVE-2026-27577 (CVSS 9.4) — code injection flaw lets authenticated users run system commands! Patch to 2.10.1/2.9.3/1.123.22 ASAP. Lock down permissions! https://radar.offseq.com/threat/cve-2026-27577-cwe-94-improper-control-of-genera... https://t.co/JOxrIWPLtH

    Post summary

    Critical code injection vulnerability in n8n allows authenticated users to execute system commands; patch to specific versions is urgently recommended.

    1000060
    270 followersView on X
  • Bryan@so_sthbryan
    Patch

    n8n patched a sandbox escape that lets workflow editors run host commands. Security Joes bypassed the February CVE-2026-27577 fix: - high severity expression sandbox escape - authenticated editor to OS command exec - runs as the n8n service user patch is out, update now https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html

    Post summary

    n8n has released a patch for a sandbox escape that enabled authenticated editors to execute host commands; the security community has highlighted a bypass demonstrating the urgency of updating.

    0000061
    184 followersView on X
  • Security Arsenal, LLC@SecurityAr58409
    Patch

    🔒 #CyberSecurity Defending Against Critical n8n RCE Flaws: Patching Guide for CVE-2026-27577 and… "Workflow automation tools like n8n have become essential components of modern IT…" 🔗 https://securityarsenal.com/blog/defending-against-critical-n8n-rce-flaws-patching-guide-for-cve-2026-27577-and-cve-2026-27493 #CyberSecurity #ThreatIntel #alertfatigue #triage #alertmonitor

    Post summary

    A patching guide is provided for two critical n8n RCE CVEs, confirming that stakeholders should apply the advised fixes.

    0000026
    10 followersView on X
  • ARCHIE@archie_sham
    General

    🚨🚨Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials🚨🚨 CVE-2026-27577 (CVSS score: 9.4) CVE-2026-27493 (CVSS score: 9.5) #n8n #CVE #Alert #Cybersecurity https://t.co/PWpyNkfCmP

    Post summary

    A tweet alerts to two critical n8n CVEs (RCE and credential exposure) with high CVSS scores, but provides no PoC, exploit, patch, or evidence of active exploitation.

    00000101
    228 followersView on X
  • Vulert@vulert_official
    Patch

    🚨 Critical n8n vulnerabilities could lead to RCE + potential credential exposure (CVE-2026-27577, CVE-2026-27493). Patch to 2.10.1 / 2.9.3 / 1.123.22 ASAP. https://vulert.com/blog/critical-n8n-vulnerabilities-rce-credential/ #CyberSecurity #AppSec #n8n #Vulert

    Post summary

    The tweet announces critical n8n CVEs that allow RCE and credential exposure, and urges users to apply the latest patches immediately.

    0000042
    124 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more