<- ALL CYBER NEWS

High

n8n, CVE-2026-27577, sandbox escape, RCE, workflow automation, self-hosted, code injection

n8n Sandbox Escape CVE-2026-27577 Runs OS Commands

n8n CVE-2026-27577 (CVSS 9.4) is a sandbox escape letting an authenticated workflow editor run OS commands on a platform holding all your credentials. Patch now.

n8n CVE-2026-27577 is a CVSS 9.4 expression-sandbox escape that lets an authenticated workflow editor run operating-system commands as the n8n process. Because n8n typically holds every credential your automations touch, an editor-level account becomes a full server-and-secrets compromise. Patch to 2.10.1, 2.9.3, or 1.123.22.

What happened. n8n patched CVE-2026-27577 (CVSS 9.4, CWE-94 code injection), an escape from the expression-evaluation sandbox. An authenticated user who can edit workflows can break out of the sandbox and execute OS commands as the n8n process. It affects versions prior to 2.10.1, 2.9.3, and 1.123.22.

How serious is CVE-2026-27577?

Detail

Value

CVE

CVE-2026-27577

CVSS

9.4 Critical (CWE-94, code injection)

Requires

An authenticated workflow editor

Effect

OS command execution as the n8n process

Fixed in

n8n 2.10.1, 2.9.3, 1.123.22

Who is affected. Teams running self-hosted n8n, especially instances exposed to the internet or shared across a team. The precondition is editor access - but that is exactly what many teams hand out freely, treating n8n as a low-risk internal tool.

Why is an n8n RCE worse than it sounds?

Because n8n is effectively a credential vault. To run automations it stores AWS keys, database passwords, and API tokens. Command execution as the n8n process therefore is not just server access - it is a path to every secret the platform was trusted with.

What should you do now?

Upgrade to n8n 2.10.1, 2.9.3, or 1.123.22 immediately. Then tighten who has editor access, take self-hosted instances off the public internet, and rotate the high-value credentials n8n holds if you cannot rule out exposure. Run n8n as an unprivileged, well-isolated container.

Our read. Automation platforms concentrate trust: one tool, holding the keys to everything it connects. That makes an "authenticated-only" sandbox escape far more serious than its precondition suggests - the blast radius is your entire secret store, not one host. Knowing which of your internal tools have quietly become crown jewels, and testing them like it, is the job point-in-time scanning skips.

Reporting by The Hacker News; severity, affected versions and CWE per NVD. Sources linked above.

Related: GitLab 18.11.3 RCE PoC runs as git and our KEV pentest analysis.

Liked this briefing? Share it:

More briefings

Related posts appear on the live page
Get the briefings first
Breaking security news, verified fast, with the one fact the headlines skip. No spam - unsubscribe anytime.