Multiple newly disclosed bugs in the popular workflow automation tool n8n could allow attackers to hijack servers, steal credentials, and quietly disrupt AI-driven business processes. The vulnerabilities, collectively tracked as CVE-2026-25049, stem from weaknesses in how n8n sanitizes expressions inside workflows and could enable authenticated users to smuggle malicious code past safeguards introduced to fix CVE-2025-68613, a December 2025 vulnerability that already carried a near-perfect severity score. The new flaws carry a CVSS rating of 9.4, though some researchers argue the real-world impact could be even worse. n8n – an open source automation platform widely used to stitch together cloud apps, internal services, and increasingly AI-driven workflows – confirmed the issue in a security advisory published Wednesday. Maintainers warned that users with permission to create or modify workflows could craft expressions that trigger unintended command execution on the host system. "Additional exploits in the expression evaluation of n8n have been identified and patched following CVE-2025-68613," n8n's maintainers said. "An authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n." The disclosure lands just weeks after another maximum-severity n8n bug dubbed "ni8mare" exposed an estimated 100,000 automation servers to takeover through an unauthent...
n8n security woes roll on as new critical flaws bypass December fix
The Register
·Carly Page
·Published Feb 5, 2026
·Updated
Affected Software
1 affected component
n8n n8n>=0.1.0
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses newly disclosed security vulnerabilities in the n8n workflow automation tool.
2
What security implications are discussed in the article?
The vulnerabilities could allow attackers to hijack servers, steal credentials, and disrupt AI-driven business processes.
3
What versions of n8n are affected by these vulnerabilities?
The vulnerabilities affect all versions of n8n starting from 0.1.0.
4
Have these vulnerabilities been previously addressed or fixed?
The article mentions that these flaws bypassed a December fix, indicating ongoing security issues.
5
What is the significance of the vulnerabilities found in n8n?
The vulnerabilities pose a critical risk to security and operational integrity for users relying on n8n for automation.