Back to Feed
VulnerabilitiesMar 11, 2026

Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials

Two critical vulnerabilities were patched in the n8n workflow automation platform, including a sandbox escape (CVE-2026-27577) and an unauthenticated flaw (CVE-2026-27493) that both enable remote code execution. Both vulnerabilities carry CVSS scores above 9.4, posing severe risks to affected deployments.

Summary

Two critical vulnerabilities were patched in the n8n workflow automation platform, including a sandbox escape (CVE-2026-27577) and an unauthenticated flaw (CVE-2026-27493) that both enable remote code execution. Both vulnerabilities carry CVSS scores above 9.4, posing severe risks to affected deployments.

Indicators of Compromise

  • cve — CVE-2026-27577
  • cve — CVE-2026-27493