CVE-2026-33660Disclosure(n8n / n8n)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflows could use the Merge node's "Combine by SQL" mode to read local files on the n8n host and achieve remote code execution. The AlaSQL sandbox did not sufficiently restrict certain SQL statements, allowing an attacker to access sensitive files on the server or even compromise the instance. The issue has been fixed in n8n versions 2.14.1, 2.13.3, and 1.123.26. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Limit workflow creation and editing permissions to fully trusted users only, and/or disable the Merge node by adding `n8n-nodes-base.merge` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 7 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 5d ago at 2 mentions (2026-03-25); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-03-25: 2Mentions · 2026-03-26: 1Mentions · 2026-03-27: 2Mentions · 2026-03-31: 1Mentions · 2026-04-01: 1Mentions · 2026-04-05: 1Patch / Workaround · 2026-03-27: 1Patch / Workaround · 2026-03-31: 1Patch / Workaround · 2026-04-01: 1Technical Details · 2026-03-25: 2Technical Details · 2026-03-26: 1Technical Details · 2026-03-27: 2Technical Details · 2026-03-31: 1Technical Details · 2026-04-01: 103-2503-2603-2703-3104-0104-05
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-03-252
Disclosure2
2026-03-261
Disclosure1
2026-03-272
Disclosure1Patch1
2026-03-311
Patch1
2026-04-011
Disclosure1
2026-04-051
General1
Full discourse8 posts
  • Qualys@qualys
    Disclosure

    A critical remote code execution vulnerability has been identified in n8n, the popular open-source workflow automation tool. Tracked as CVE-2026-33660 with a CVSS score of 9.4, this flaw allows authenticated attackers to bypass sandboxing and execute arbitrary commands on the host system. Read the technical breakdown and mitigation steps on the Qualys blog. https://threatprotect.qualys.com/2026/03/30/n8n-patches-critical-remote-code-execution-vulnerability-cve-2026-33660/ #Cybersecurity #n8n #VulnerabilityManagement

    Post summary

    A critical RCE vulnerability (CVE‑2026‑33660) in n8n allows authenticated attackers to bypass sandboxing and execute arbitrary commands; mitigation steps are detailed on the Qualys blog.

    0301241.0K
    34.2K followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical vulnerabilities identified in #n8n. #CVE-2026-33696 #CVE-2026-33660 #CVE-2026-33713. These #RCE and #SQLi flaws allow for complete system compromise. #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-n8n-patch-immediately

    Post summary

    The post announces critical RCE and SQLi vulnerabilities in n8n and urges users to apply patches immediately.

    00001199
    7.2K followersView on X
  • Vulert@vulert_official
    Disclosure

    🚨🚨 Critical RCE flaw in n8n CVE-2026-33660 allows remote code execution through the Merge node’s SQL mode. 🔗 https://vulert.com/vuln-db/CVE-2026-33660 🛡️ #CyberSecurity #n8n #RCE #CVE202633660 #AppSec #DevSecOps #OpenSourceSecurity https://t.co/Vwuq5VKuBN

    Post summary

    A critical RCE vulnerability (CVE-2026-33660) in n8n’s Merge node’s SQL mode is disclosed, with no PoC, exploitation code, patch, or evidence of active exploitation reported.

    0001051
    122 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-33660: n8n H... AlaSQL sandbox bypass in n8n's Merge node turns SQL queries into RCE + LFI goldmine - 9.4 CVSS with auth bypass potential #n8n #RCE #SQLInjection. https://zerodaysignal.com/vulnerability/CVE-2026-33660 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The tweet announces the newly disclosed CVE-2026-33660 in n8n, noting a sandbox bypass in the Merge node that enables RCE, LFI, and possible auth bypass with a CVSS score of 9.4, and provides a link for further details.

    1000092
    168 followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-33660: n8n Workflow Merge Node Bug - What It Means for Your Business and How to Respond https://hubs.li/Q049D-ZW0

    Post summary

    The provided text is a generic title that mentions CVE‑2026‑33660 but offers no technical, exploit, or patch details.

    0000035
    30 followersView on X
  • The Daily Tech Feed@dailytechonx
    Patch

    Critical n8n vulnerability (CVE-2026-33660) exposes servers to remote code execution. Immediate patching required to prevent exploitation. Link: https://thedailytechfeed.com/critical-n8n-vulnerability-exposes-servers-to-remote-code-execution/ #Security #Vulnerability #Patch #Code #Execution #Servers #Exploitation #Protection #Network #Software #Threat #Update #CVE #Risk #Tech #Remote #Urgent #Alert #System #Defense

    Post summary

    The post alerts about a critical n8n vulnerability (CVE-2026-33660) that permits remote code execution and stresses the urgency of applying patches, without mentioning active exploitation or proof of concept details.

    0000012
    269 followersView on X
  • PulsePatch.io@pulsepatchio
    Disclosure

    Multiple RCE vulnerabilities affect n8n in Merge Node AlaSQL SQL Mode (CVE-2026-33660). Review workflows for exposure. Monitor for official patches. #n8n #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-33660-n8n-rce-merge-node

    Post summary

    The tweet announces multiple RCE vulnerabilities in n8n Merge Node AlaSQL SQL Mode (CVE-2026-33660), urging users to review workflows and stay alert for official patches.

    0000049
    3 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-33660 n8n is an open source workflow automation platform. Prior to versions 2.14.1, 2.13.3, and 1.123.26, an authenticated user with permission to create or modify workflow… https://www.cve.org/CVERecord?id=CVE-2026-33660

    Post summary

    CVE-2026-33660 reveals a flaw in n8n that allows authenticated users with workflow creation or modification rights to exploit before versions 2.14.1, 2.13.3, and 1.123.26.

    00000147
    56.8K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.14.0node.js-

Explore more