003
ID: f22bd883-4f5f-4170-bc16-74458e28f38a
STIX ID: report--f22bd883-4f5f-4170-bc16-74458e28f38a
Threat Score
78/100
Uploaded: 2026-05-14
Published Date: 2026-05-14
Last Modified Date: 2026-05-14
Created by: Thesis Research
TLP:GREEN
...
...
A critical remote code execution vulnerability in the n8n workflow automation platform (CVE-2026-25049, CVSS 9.4) allows authenticated users with workflow creation/editing permissions to bypass expression-sandbox sanitization and execute arbitrary system commands; attackers can expose public webhooks to trigger payloads and potentially compromise servers, steal credentials, exfiltrate data, and install persistent backdoors. n8n published fixes (e.g., 1.123.17, 2.5.2) and additional advisories covering a set of related high-severity CVEs; recommended mitigations include updating to patched versions, restricting workflow creation/editing to trusted users, and hardening deployment environments with additional runtime input validation.
