[CIVN-2026-0154] Multiple Vulnerabilities in n8n

By Published On: March 25, 2026

—–BEGIN PGP SIGNED MESSAGE—–

Hash: SHA256


Multiple Vulnerabilities in n8n


Indian – Computer Emergency Response Team (https://www.cert-in.org.in)


Severity Rating: CRITICAL


Software Affected


n8n versions prior to 2.10.1

n8n versions prior to 2.9.3

n8n versions prior to 1.123.22

Overview


Multiple vulnerabilities have been reported in n8n workflow automation platform which could allow an attacker to execute arbitrary code on the targeted system.


Target Audience:

All end-user organizations responsible for deploying, securing, and maintaining n8n.


Risk Assessment:

Very high risk of remote code execution and system compromise.


Impact Assessment:

Potential for unauthorized access, full system takeover, exposure of credentials and sensitive data.


Description


n8n is a workflow automation platform that allows you to connect different apps, APIs, and services to automate tasks using a visual, node-based workflow builder. It is a low-code, open-source tool commonly used to automate business processes and integrate software systems.


These vulnerabilities exist in n8n workflow automation platform due to an eval injection vulnerability (improper expression evaluation) and Expression sandbox escape flaw.


Successful exploitation of these vulnerabilities could allow an attacker to execute arbitrary code on the targeted system.


Solution


Apply appropriate security updates as mentioned in

https://n8n.io/legal/security/



Vendor Information


n8n

https://n8n.io/


References


 

https://thehackernews.com/2026/03/critical-n8n-flaws-allow-remote-code.html


CVE Name

CVE-2026-27493

CVE-2026-27577




– —


Thanks and Regards,

CERT-In


Incident Response Help Desk

e-mail: incident@cert-in.org.in

Phone: +91-11-22902657

Toll Free Number: 1800-11-4949

Toll Free Fax : 1800-11-6969

Web: http://www.cert-in.org.in

PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4

PGP Key information:

https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS


Postal address:

Indian Computer Emergency Response Team (CERT-In)

Ministry of Electronics and Information Technology

Government of India

Electronics Niketan

6, C.G.O. Complex

New Delhi-110 003

—–BEGIN PGP SIGNATURE—–


iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmnD7sQACgkQ3jCgcSdc

ys+xIA/8Ca629XE2ajmej8iEAzPc1Yt1CGD34siGDBGVC+umTbiz9KhoUVBscGP9

Zua+o/jAwno9QkiT4Kk474r9cmPV1+9broHMhGNcKq0N8gtve8aDlMNze9c5MFy4

2r335UsXywkMZoSJO2wR5GEZhVxBjzi3fCxZf1su16uXyzmaBIKpCv9XOF+ayqnv

RwqYja2L405vBagSMap795KZnzfwm8QAYM5W+rdUsuw8lcMIVSum6qzGHBhbPiFz

pRRz3VHvgpRT6naScZOumQfG6JiT2GuRfbWybbhzIS/nGyW5dl3TjVrv57zzveQ+

RcYMuCtRdIEZL8KOB12WJW5LpT274a4Tt+AWJZ/PttYAjfDatxXxMnmSlzcNjS77

JMsehVza4umQRvlNW4A5A1+KV/IHGuW2y/gQ8SxLyZ2qreXDU6jRFWj8wzBqyHhx

Ej8vXRnHTMXWQjhAUghPUaeMRVTPIxUkCpPenDvr1FDPpkVS/jgreAetG+PuQcV6

ILc6EXZAsKGT5d8wvgWfNNG7tx3cNEXxQJQisD95vBeLt541IjM7K4Uk/Y9dieVw

8JP9CHn+C6izSnohT/UXACle3lzK9E5LFySzslgmqhmhfqPgJSNlGLxnW2E5CU92

Ls6QtYeSzesA+LsEKdT2R0sZ5Lb76WjyMz9nn5bBDBVTo9i54Ns=

=RMfc

—–END PGP SIGNATURE—–

Share this article