
[CIVN-2026-0154] Multiple Vulnerabilities in n8n
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Multiple Vulnerabilities in n8n
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
n8n versions prior to 2.10.1
n8n versions prior to 2.9.3
n8n versions prior to 1.123.22
Overview
Multiple vulnerabilities have been reported in n8n workflow automation platform which could allow an attacker to execute arbitrary code on the targeted system.
Target Audience:
All end-user organizations responsible for deploying, securing, and maintaining n8n.
Risk Assessment:
Very high risk of remote code execution and system compromise.
Impact Assessment:
Potential for unauthorized access, full system takeover, exposure of credentials and sensitive data.
Description
n8n is a workflow automation platform that allows you to connect different apps, APIs, and services to automate tasks using a visual, node-based workflow builder. It is a low-code, open-source tool commonly used to automate business processes and integrate software systems.
These vulnerabilities exist in n8n workflow automation platform due to an eval injection vulnerability (improper expression evaluation) and Expression sandbox escape flaw.
Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the targeted system.
Solution
Apply appropriate security updates as mentioned in
https://n8n.io/legal/security/
Vendor Information
n8n
https://n8n.io/
References
https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html
CVE Name
CVE-2026-27493
CVE-2026-27577
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnD7sQACgkQ3jCgcSdc
ys+xIA/8Ca629XE2ajmej8iEAzPc1Yt1CGD34siGDBGVC+umTbiz9KhoUVBscGP9
Zua+o/jAwno9QkiT4Kk474r9cmPV1+9broHMhGNcKq0N8gtve8aDlMNze9c5MFy4
2r335UsXywkMZoSJO2wR5GEZhVxBjzi3fCxZf1su16uXyzmaBIKpCv9XOF+ayqnv
RwqYja2L405vBagSMap795KZnzfwm8QAYM5W+rdUsuw8lcMIVSum6qzGHBhbPiFz
pRRz3VHvgpRT6naScZOumQfG6JiT2GuRfbWybbhzIS/nGyW5dl3TjVrv57zzveQ+
RcYMuCtRdIEZL8KOB12WJW5LpT274a4Tt+AWJZ/PttYAjfDatxXxMnmSlzcNjS77
JMsehVza4umQRvlNW4A5A1+KV/IHGuW2y/gQ8SxLyZ2qreXDU6jRFWj8wzBqyHhx
Ej8vXRnHTMXWQjhAUghPUaeMRVTPIxUkCpPenDvr1FDPpkVS/jgreAetG+PuQcV6
ILc6EXZAsKGT5d8wvgWfNNG7tx3cNEXxQJQisD95vBeLt541IjM7K4Uk/Y9dieVw
8JP9CHn+C6izSnohT/UXACle3lzK9E5LFySzslgmqhmhfqPgJSNlGLxnW2E5CU92
Ls6QtYeSzesA+LsEKdT2R0sZ5Lb76WjyMz9nn5bBDBVTo9i54Ns=
=RMfc
—–END PGP SIGNATURE—–


