• News/
  • https://www.bleepingcomputer.com/news/security/critical-n8n-flaws-disclosed-along-with-public-exploits/

Critical n8n flaws disclosed along with public exploits

BleepingComputer
·
Bill Toulas
·
Published Feb 4, 2026
·
Updated

Multiple critical vulnerabilities in the popular n8n open-source workflow automation platform allow escaping the confines of the environment and taking complete control of the host server. Collectively tracked as CVE-2026-25049, the issues can be exploited by any authenticated user who can create or edit workflows on the platform to perform unrestricted remote code execution on the n8n server. Researchers at several cybersecurity companies reported the problems, which stem from n8n's sanitization mechanism and bypass the patch for CVE-2025-68613, another critical flaw addressed on December 20. According to Pillar Security, exploiting CVE-2026-25049 enables complete compromise of the n8n instance and could be leveraged to run arbitrary system commands on the server, steal all stored credentials, secrets (API keys, OAuth tokens), and sensitive configuration files. By exploiting the vulnerability, the researchers were also able to access the filesystem and internal systems, pivot to connected cloud accounts, and hijack AI workflows (intercept prompts, modify responses, redirect traffic). As n8n is a multi-tenant environment, accessing internal cluster services can potentially allow pivoting to other tenants’ data. “The attack requires nothing special. If you can create a workflow, you can own the server,” Pillar Security says in a report today. Pillar’s report describes the problem as incomplete AST-based sandboxing and explains that it arises from n8n’s weak sandboxing of user...

Read full article

Affected Software

1 affected component
n8n n8n<2.5.2, <1.123.17

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses critical vulnerabilities in the n8n open-source workflow automation platform.

2

What security implications are discussed in the article?

The vulnerabilities allow attackers to escape the environment's confines and gain complete control of the host server.

3

What are the CVE identifiers associated with these vulnerabilities?

The vulnerabilities are collectively tracked as CVE-2026-25049.

4

What versions of n8n are affected by these vulnerabilities?

The affected versions of n8n are prior to 2.5.2 and 1.123.17.

5

Are there public exploits available for these vulnerabilities?

Yes, the article mentions that public exploits have been disclosed for these critical vulnerabilities.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203