Close Menu
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice

Subscribe to Updates

Get the latest creative news from FooBar about art, design and business.

What's Hot

New CISA Guide Helps Agencies Adopt SASE For Zero Trust

June 25, 2026

Microsoft Confirms RoguePlanet Defender Zero-Day, Says Patch is in Development

June 25, 2026

Trust in Automated AI Vulnerability Scanning Collapses to 9%

June 25, 2026
Facebook X (Twitter) Instagram
Friday, June 26
Facebook X (Twitter) Instagram Pinterest Vimeo
Cyberwire Daily
  • Home
  • News
  • Cyber Security
  • Internet of Things
  • Tips and Advice
Cyberwire Daily
Home»Cyber Security»Critical and High Severity n8n Sandbox Flaws Allow RCE
Cyber Security

Critical and High Severity n8n Sandbox Flaws Allow RCE

Team-CWDBy Team-CWDJanuary 28, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest LinkedIn Tumblr Reddit Telegram Email
Share
Facebook Twitter LinkedIn Pinterest Email


Two serious security flaws affecting the n8n workflow automation platform have exposed weaknesses in the product’s sandboxing mechanisms for JavaScript and Python code.

The vulnerabilities, disclosed by the JFrog Security Research team, could allow authenticated attackers to run arbitrary commands on systems hosting vulnerable n8n instances, including the company’s cloud service and self-hosted deployments that have not been patched.

n8n is a widely adopted automation platform that blends AI-driven capabilities with business process orchestration. Because workflows often require custom scripting, the platform relies on sandbox controls designed to prevent user-supplied code from accessing the underlying operating system. According to the researchers, those controls can be bypassed despite recent security improvements.

The first flaw, tracked as CVE-2026-1470 and rated a CVSS 3.1 score of 9.9 Critical, affects n8n’s JavaScript expression engine. The second, CVE-2026-0863, is rated 8.5 High and impacts Python execution in the Code node when running in “Internal” mode.

In both cases, the researchers demonstrated that gaps in abstract syntax tree validation could be abused to escape the sandbox and achieve full remote code execution (RCE).

Exploitation requires the ability to create or modify workflows, a capability often granted to legitimate users. Once abused, the vulnerabilities allow attackers to execute commands in the context of the main n8n service, potentially exposing environment variables, sensitive data and system-level access.

Read more on workflow automation security: Maximum Severity “Ni8mare” Bug Lets Hackers Hijack n8n Servers

In the JavaScript issue, the researchers found that the sandbox logic did not adequately handle a deprecated yet still-supported language feature: the with statement.

By manipulating how identifiers were resolved, they were able to indirectly access the Function constructor and execute arbitrary code. The vulnerability was considered particularly severe because the code ran directly within n8n’s primary process.

The Python flaw stemmed from a different class of weakness. While n8n uses a highly restrictive policy that blocks imports and many built-in functions, the researchers showed that Python’s string formatting and changes introduced in Python 3.10 could be combined to recover restricted objects through exception handling. This made it possible to bypass the sandbox even without direct access to forbidden functions.

n8n users are advised to upgrade as soon as possible. CVE-2026-1470 is fixed in versions 1.123.17, 2.4.5 and 2.5.1, while CVE-2026-0863 is addressed in versions 1.123.14, 2.3.5 and 2.4.2. All earlier versions remain vulnerable.

Image credit: Stock all / Shutterstock.com



Source

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticleAutonomous System Uncovers Long-Standing OpenSSL Flaws
Next Article SmarterMail Auth Bypass Exploited in the Wild Two Days After Patch Release
Team-CWD
  • Website

Related Posts

Cyber Security

Cisco Vulnerability Exploited Months Before Disclosure, Google Warns

June 25, 2026
Cyber Security

Iran-Linked MuddyWater Poses as Ransomware Gang to Mask Espionage

June 25, 2026
Cyber Security

UK Museums Face Cybersecurity Risks, MPs Warn

June 24, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest News

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views

Why SOC Burnout Can Be Avoided: Practical Steps

November 14, 20259 Views

Cyber M&A Roundup: Cyber Giants Strengthen AI Security Offerings

December 1, 20258 Views
Stay In Touch
  • Facebook
  • YouTube
  • TikTok
  • WhatsApp
  • Twitter
  • Instagram
Most Popular

North Korean Hackers Turn JSON Services into Covert Malware Delivery Channels

November 24, 202522 Views

macOS Stealer Campaign Uses “Cracked” App Lures to Bypass Apple Securi

September 7, 202517 Views

North Korean Hackers Target Crypto Firms with ClickFix and Zoom Lures

April 29, 202610 Views
Our Picks

Children and chatbots: What parents should know

January 23, 2026

How chatbots can help spread scams

October 14, 2025

What’s at stake if your employees post too much online

December 1, 2025

Subscribe to Updates

Get the latest news from cyberwiredaily.com

Facebook X (Twitter) Instagram Pinterest
  • Home
  • Contact
  • Privacy Policy
  • Terms of Use
  • California Consumer Privacy Act (CCPA)
© 2026 All rights reserved.

Type above and press Enter to search. Press Esc to cancel.