New n8n Vulnerabilities CVE-2026-25049 Allow Server Hijacking and Credential Theft
- Securityish
- Threats & Incidents
Quick Summary
The Securityish Brief
n8n, a popular open-source automation platform, has disclosed critical vulnerabilities collectively known as CVE-2026-25049. These flaws, identified in a security advisory published on a Wednesday, stem from issues in how the platform sanitizes expressions within workflows. This vulnerability allows authenticated users with the ability to create or modify workflows to execute unintended commands on the host system.
The vulnerabilities have a CVSS rating of 9.4, indicating their high severity. This follows a previous vulnerability, CVE-2025-68613, which also had a near-perfect severity score. The recent disclosure comes shortly after another severe bug, dubbed ‘ni8mare,’ which exposed around 100,000 automation servers to unauthorized access through an unauthenticated remote code execution flaw.
Security experts from Pillar Security, who disclosed these new vulnerabilities, highlighted the risks associated with automation platforms like n8n. These platforms often handle sensitive information, making them attractive targets for attackers. Successful exploitation could grant attackers full control over vulnerable servers, potentially leaking stored workflow credentials, including API keys and tokens used for cloud and AI services.
Researchers demonstrated that exploitation of these vulnerabilities requires minimal effort. For instance, an attacker could create a workflow using a public webhook without authentication, inserting malicious JavaScript to execute commands at the system level. This type of attack could allow unauthorized users to interact with the server hosting n8n.
The implications of these vulnerabilities extend beyond individual users, particularly for n8n Cloud users. The platform’s multi-tenant architecture could allow a malicious user to access data from other customers if the flaw is exploited. This raises significant privacy and security concerns for organizations relying on n8n for automation.
As automation tools become increasingly integrated into daily operations, the potential for undetected breaches grows. Attackers can extract sensitive data while workflows continue to run normally, making detection challenging.
- CVE-2026-25049: A critical vulnerability in n8n that allows authenticated users to execute unintended commands on the host system.
- CVE-2025-68613: A previous vulnerability in n8n that also had a high severity score, related to expression evaluation.
- ni8mare: A severe bug that exposed around 100,000 automation servers to unauthorized access through an unauthenticated remote code execution flaw.
- Pillar Security: The security firm that disclosed the new vulnerabilities and highlighted the risks associated with automation platforms.
- n8n Cloud: The hosted version of n8n that may expose customer data due to its multi-tenant architecture.
Key Takeaways
- Update n8n immediately to the latest version to patch the vulnerabilities.
- Review user permissions to ensure only authorized individuals can create or modify workflows.
- Examine existing workflows for potential security risks and vulnerabilities.
- Rotate sensitive credentials, especially those linked to cloud or AI services.
- Monitor automation workflows for unusual activity that could indicate a breach.
Key Terms & Concepts
- CVE-2026-25049: In this article, CVE-2026-25049 refers to a critical vulnerability in n8n that allows authenticated users to execute unintended commands on the host system.
- CVE-2025-68613: CVE-2025-68613 is a previous vulnerability in n8n related to expression evaluation, which also had a high severity score.
- ni8mare: The ni8mare bug exposed around 100,000 automation servers to unauthorized access through an unauthenticated remote code execution flaw.
- Pillar Security: Pillar Security is the security firm that disclosed the new vulnerabilities in n8n and emphasized the risks associated with automation platforms.
- n8n Cloud: n8n Cloud is the hosted version of n8n that may expose customer data due to its multi-tenant architecture.
Your 5-Minute Securityish Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.
Securityish
Securityish explains cybersecurity, scams, data breaches, and privacy risks in simple language so you know what’s happening and how to protect yourself.
Navigation
Your 5-Minute Cybersecurity Brief
A weekly digest of cybersecurity news, phishing alerts, privacy tips, and emerging threats, simplified so anyone can understand what matters and why.