A critical remote code execution issue in the n8n open-source workflow automation platform, tracked as CVE-2026-25049 (also published as GHSA-6cqr-8cfr-67f8), allows an authenticated user with permission to create or modify workflows to escape n8n’s expression sandbox and execute arbitrary system commands on the underlying host. The flaw stems from insufficient input sanitization/weak sandboxing in n8n’s expression evaluation (server-side JavaScript) and was identified during follow-up analysis after an earlier critical n8n vulnerability (CVE-2025-68613) was patched; researchers report the new issue effectively bypasses prior mitigations.
Reporting indicates exploitation can lead to full compromise of the n8n instance, including access to the filesystem and the ability to steal stored credentials and secrets (e.g., API keys, OAuth tokens) and sensitive configuration, with potential for pivoting into connected internal services and cloud accounts in multi-tenant deployments. Public reporting also notes public exploits are available. n8n maintainers state the issue is patched, and affected organizations should upgrade to fixed releases (1.123.17 and 2.5.2), as versions prior to 1.123.17 and 2.5.2 are impacted.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
8 events from the most recent confirmed update back to the earliest known activity.
A pull request was opened in the ProjectDiscovery nuclei-templates repository to add a detection template for CVE-2026-25049. The template checks exposed n8n instances for vulnerable versions by parsing version information from the /signin page and comparing it against the fixed releases.
Security reporting highlighted a broader set of three critical n8n vulnerabilities—CVE-2026-25053, CVE-2026-25056, and CVE-2026-25049—affecting the Git node, Merge node, and expression engine. The flaws could allow authenticated workflow editors to read or write files and achieve host takeover, prompting calls for immediate upgrades.
Alongside the CVE-2026-25049 disclosure, n8n issued alerts for 11 other vulnerabilities, including critical issues involving command injection, file access races, sandbox escapes, and XSS. Fixed versions were provided for the affected branches.
Researchers published technical write-ups and proof-of-concept exploitation methods showing how crafted workflow expressions could escape n8n's sandbox using techniques such as access to the Node.js global object and the Function constructor. Reports also highlighted that public webhooks could make exploitation easier once a malicious workflow is in place.
n8n released patched versions 1.123.17 and 2.5.2 to address CVE-2026-25049 and urged users to update immediately. The company also recommended restricting workflow permissions, hardening deployments, and rotating encryption keys and credentials after patching.
n8n publicly disclosed CVE-2026-25049 via GitHub Security Advisory GHSA-6cqr-8cfr-67f8, describing a critical sandbox-escape flaw in workflow expressions that can lead to remote code execution. The advisory said affected versions were all releases before 1.123.17 and 2.5.2.
Multiple researchers and vendors, including Pillar Security, Endor Labs, SecureLayer7, and Fatih Çelik, identified new sandbox-escape techniques in n8n's expression engine that allowed authenticated workflow editors to achieve host command execution. Their work showed the issue was a bypass of the earlier CVE-2025-68613 mitigation.
n8n patched the earlier critical expression-evaluation flaw CVE-2025-68613 in December 2025. Later reporting said CVE-2026-25049 was discovered during follow-up work and bypassed protections added in that fix.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
8 references tracked. Mallory keeps watching after this page renders.
github.com
Open sourcesecurityonline.info
Open sourcecybersecuritynews.com
Open sourcego.theregister.com
Open sourcesocradar.io
Open sourcethecyberexpress.com
Open sourcethehackernews.com
Open sourcebleepingcomputer.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.