HomeSecuritySix new vulnerabilities discovered in the n8n automation platform

Six new vulnerabilities discovered in n8n automation platform

Six new vulnerabilities have been discovered in the n8n workflow platform, which is used to build AI agents to connect business processes. Four of the six vulnerabilities have been rated critical, with CVSS severity scores of 9.4.

See also: Critical vulnerability n8η allows execution of system commands

n8n

“These vulnerabilities span multiple attack classes, from remote code execution and command injection to arbitrary file access and cross-site scripting, targeting a platform that is often deployed with access to secrets, credentials, internal APIs, and business logic critical to the enterprise,” noted Amit Genkin, a security researcher at Israeli cloud security firm Upwind, who wrote about the vulnerabilities this week.

Johannes Ullrich, dean of research at the SANS Institute, said the vulnerabilities affect how n8n isolates processes created by different users and how the host is protected from users with access to n8n. The discovery is the second major disclosure of issues in the n8n platform this year.

Four weeks ago, researchers at Cyera published details of a critical vulnerability, once patched, that would have allowed unauthenticated attackers to take over n8th deployments. Also last month, it was reported that malicious actors are targeting n8th by planting malicious packages in the npm registry that claim to be legitimate n8th add-ons. CSOs with n8th in their environments and developers using the platform should update to the latest version of the application to close the newly discovered holes.

The vulnerabilities are:

CVE-2026-21893, a command injection vulnerability in the n8n community release. An unauthenticated user with administrative privileges could execute arbitrary system commands on the n8n host. It has a CVSS score of 9.4

CVE-2026-25049, which has a CVSS score of 9.4. An authenticated user with permissions to create or modify workflows could exploit expressions crafted in workflow parameters to cause unpredictable execution of system commands on the host running n8th.

See also: Two serious vulnerabilities in n8th allow RCE

Six new vulnerabilities discovered in n8n automation platform

CVE-2026-25052, which has a CVSS score of 9.4. A vulnerability in file access controls allows authenticated users with permissions to create or modify workflows to read sensitive files from the n8n host system.

CVE-2026-25053, which has a CVSS score of 9.4. This is a vulnerability in Git node that allows execution of system commands or arbitrary file access.

CVE-2026-25051, a cross-site scripting vulnerability in the handling of webhook responses and related HTTP endpoints. It has a CVSS score of 8.5.

CVE-2025-61917, which has a CVSS score of 7.7. An information disclosure vulnerability caused by unsafe buffer allocation in n8n task executors.

During an interview, Moshe Hassan, Upwind’s vice president of research and innovation, estimated that 83% of his company’s customers use the n8th platform. However, he added, less than 25% are using it in production and/or may have it exposed online. The rest, he said, are testing it.

However, he said those evaluating the platform could be at risk if users enter identity tokens for cloud platforms like AWS and others as part of their testing.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

See also: New vulnerability in n8η allows arbitrary command execution

Six new vulnerabilities discovered in n8n automation platform

In general, to mitigate vulnerabilities, CSOs need to understand the business logic and data flow of any applications in their environments, Hassan noted. However, risk can be reduced through network segregation, he said, and in addition, engineering should be allowed to create sandboxes for detailed testing of applications before they are put into production.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS