• News/
  • https://www.bleepingcomputer.com/news/security/new-sandbox-escape-flaw-exposes-n8n-instances-to-rce-attacks/

New sandbox escape flaw exposes n8n instances to RCE attacks

BleepingComputer
·
Bill Toulas
·
Published Jan 28, 2026
·
Updated

Two vulnerabilities in the n8n workflow automation platform could allow attackers to fully compromise affected instances, access sensitive data, and execute arbitrary code on the underlying host. Identified as CVE-2026-1470 and CVE-2026-0863, the vulnerabilities were discovered and reported by researchers at DevSecOps company JFrog. Despite requiring authentication, CVE-2026-1470 received a critical severity score of 9.9 out of 10. JFrog explained that the critical rating was due to arbitrary code execution occurring in n8n’s main node, which allows complete control over the n8n instance. n8n is an open-source workflow automation platform that lets users link applications, APIs, and services into complex processes using a visual editor. With more than 200,000 weekly downloads on npm, the library is used for task automation and supports integrations with AI and large language model (LLM) services. The two vulnerabilities discovered by JFrog can be summarized as follows: "These vulnerabilities highlight how difficult it is to safely sandbox dynamic, high‑level languages such as JavaScript and Python," JFrog explains. "Even with multiple validation layers, deny lists, and AST‑based controls in place, subtle language features and runtime behaviors can be leveraged to bypass security assumptions," the researchers say. Exploiting CVE-2026-1470 requires authentication because permissions to create or modify a workflow are necessary to escape the sandbox and execute commands on the ...

Read full article

Affected Software

1 affected component
n8n workflow automation platform>=1.0<1.123.14, >=2.0<2.4.2, >=1.123.14<=1.123.17, >=2.4.2<=2.4.5, >=2.4.5<=2.5.1
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What vulnerabilities are reported in the article regarding n8n?

The article reports two vulnerabilities identified as CVE-2026-1470 and CVE-2026-0 that could allow remote code execution.

2

What is the security threat posed by these vulnerabilities in n8n?

These vulnerabilities can lead to full compromise of affected n8n instances, enabling attackers to access sensitive data and execute arbitrary code on the underlying host.

3

Which versions of n8n are affected by the reported vulnerabilities?

The affected n8n versions include 1.0 to 1.123.14, 2.0 to 2.4.2, as well as specific updates between 1.123.14 to 1.123.17, 2.4.2 to 2.4.5, and 2.4.5 to 2.5.1.

4

What should users of n8n do to mitigate the risks associated with these vulnerabilities?

Users of n8n should update to the latest versions that address these vulnerabilities as soon as possible to mitigate the risks.

5

Who compiled the report on the vulnerabilities affecting n8n?

The vulnerabilities affecting n8n were reported and highlighted by security researchers and shared in a security news article.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203