Cybersecurity researchers have uncovered two new vulnerabilities in the workflow automation platform n8n, including a critical vulnerability that could lead to remote code execution.
See also: New vulnerability in n8n allows arbitrary command execution

The vulnerabilities, discovered by the JFrog Security Research, are as follows:
CVE-2026-1470 (CVSS score: 9.9) – An eval injection vulnerability that could allow an authenticated user to bypass the Expression sandbox mechanism and achieve full remote code execution on the n8η master node by passing specially crafted JavaScript code.
CVE-2026-0863 (CVSS score: 8.5) – An eval injection vulnerability that could allow an authenticated user to bypass the sandbox restrictions of n8n's python-task-executor and execute arbitrary Python code on the underlying operating system.
Successful exploitation of these vulnerabilities could allow an attacker to take over an entire n8n installation, including scenarios where it is running in “internal” execution mode. In its documentation, n8n notes that using internal mode in production environments can pose a security risk, urging users to switch to external mode to ensure proper isolation between n8n processes and the task runner.
See also: Critical vulnerability in n8n allows code execution

To address the gaps, users are advised to update to the latest versions.
This development comes just a few weeks after Cyera Research Labs analyzed a maximum severity vulnerability in n8n (CVE-2026-21858, also known as Ni8mare) that allows an unauthenticated remote attacker to gain complete control over vulnerable installations.
“These vulnerabilities highlight how difficult it is to create a secure sandbox for dynamic, high-level languages like JavaScript and Python,” said researcher Nathan Nehorai. “Even with multiple levels of validation, deny lists, and AST-based checks, subtle language features and runtime behaviors can be exploited to circumvent security assumptions.”
See also: Critical vulnerability in Grist-Core allows RCE attacks

“In this case, obsolete or rarely used constructs, combined with changes to the interpreter and exception handling behavior, were enough to escape otherwise restrictive sandboxes and achieve remote code execution.“
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
