logo

003

ID: f22bd883-4f5f-4170-bc16-74458e28f38a

STIX ID: report--f22bd883-4f5f-4170-bc16-74458e28f38a

Threat Score

78/100

Uploaded: 2026-05-14

Published Date: 2026-05-14

Last Modified Date: 2026-05-14

Created by: Thesis Research

TLP:GREEN
...
...
A critical remote code execution vulnerability in the n8n workflow automation platform (CVE-2026-25049, CVSS 9.4) allows authenticated users with workflow creation/editing permissions to bypass expression-sandbox sanitization and execute arbitrary system commands; attackers can expose public webhooks to trigger payloads and potentially compromise servers, steal credentials, exfiltrate data, and install persistent backdoors. n8n published fixes (e.g., 1.123.17, 2.5.2) and additional advisories covering a set of related high-severity CVEs; recommended mitigations include updating to patched versions, restricting workflow creation/editing to trusted users, and hardening deployment environments with additional runtime input validation.