CVE-2026-25049: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-25049 is an expression sandbox escape vulnerability in n8n, an open-source workflow automation platform, that allows authenticated users with workflow creation or modification permissions to execute arbitrary system commands on the host running n8n. Disclosed on February 4, 2026, it affects all n8n versions prior to 1.123.17 (1.x branch) and prior to 2.5.2 (2.x branch, starting from 2.0.0). The vulnerability is classified as Critical with a CVSS v4.0 base score of 9.4 and a CVSS v3.1 base score of 9.9 (GitHub Advisory, n8n Security Advisory). This issue follows and extends CVE-2025-68613, a prior expression evaluation vulnerability in the same platform.

Technical details

The root cause is classified as CWE-913 (Improper Control of Dynamically-Managed Code Resources), specifically a failure to properly sandbox expression evaluation within n8n workflow parameters (GitHub Advisory). An attacker crafts malicious expressions embedded in workflow node parameters that escape the intended expression evaluation sandbox, causing the underlying Node.js runtime to execute arbitrary operating system commands. Exploitation requires only low-level authenticated access (e.g., a standard user account with workflow edit permissions) and no user interaction, making it highly accessible to insider threats or compromised accounts. Public proof-of-concept code demonstrating the sandbox escape technique is available at PoC GitHub, and additional technical analysis has been published by multiple security researchers (Pillar Security Blog, SOCRadar).

Impact

Successful exploitation grants an attacker arbitrary command execution on the host operating system running n8n, with the privileges of the n8n service account. This can lead to complete system compromise, unauthorized access to sensitive data stored on the host or accessible via the network, data manipulation, service disruption, and lateral movement within the broader infrastructure (GitHub Advisory, Pillar Security Blog). Given that n8n is widely deployed in enterprise AI and automation environments — with hundreds of thousands of instances reported — the potential blast radius is significant (eSecurity Planet). The CVSS v4.0 score reflects high impact across confidentiality, integrity, and availability for both the vulnerable and subsequent systems.

Exploitability

A public proof-of-concept exploit is available on GitHub (PoC GitHub), and active exploitation in the wild has been reported by multiple sources including BleepingComputer (BleepingComputer). CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in March 2026, ordering federal agencies to patch (The Register). The EPSS score is approximately 0.026% (low automated exploitation probability), but real-world exploitation has been confirmed. Detection signatures have been published by Qualys (IDs: 733668, 5007426, 530913) and Nessus (ID: 298984), and a Nuclei template pull request was submitted to ProjectDiscovery (Feedly).

Exploitation steps

  1. Reconnaissance: Identify internet-facing or internally accessible n8n instances running versions below 1.123.17 or 2.5.2 using tools like Shodan, Censys, or internal network scanning.
  2. Obtain authenticated access: Log in to the n8n instance using a valid account that has permission to create or modify workflows. This could be a compromised user account, a free trial account, or an insider threat.
  3. Create or modify a workflow: Navigate to the n8n workflow editor and create a new workflow or edit an existing one.
  4. Inject malicious expression: In a workflow node parameter that supports n8n expressions (denoted by {{ }}), craft a payload that escapes the expression sandbox. Based on the sandbox escape technique (CWE-913), this involves abusing JavaScript prototype chain access or constructor references to reach Node.js built-ins such as process or child_process. Example pattern: {{ $evaluateExpression('...constructor.constructor("return process")().mainModule.require("child_process").execSync("id")') }}.
  5. Execute the workflow: Trigger the workflow manually or via a webhook/schedule, causing n8n to evaluate the malicious expression and execute the injected OS command on the host.
  6. Achieve post-exploitation objectives: Use the RCE foothold to establish a reverse shell, exfiltrate credentials or sensitive data, pivot to other systems, or install persistence mechanisms (GitHub Advisory, PoC GitHub, BleepingComputer).

Indicators of compromise

  • Network: Unexpected outbound connections from the n8n host to external IPs or domains, particularly on non-standard ports; reverse shell traffic (e.g., TCP connections to attacker-controlled infrastructure).
  • Logs: n8n application logs showing unusual expression evaluation errors or unexpected workflow executions; audit logs recording workflow creation or modification by low-privilege accounts followed immediately by execution.
  • Process: Unusual child processes spawned by the n8n Node.js process (e.g., sh, bash, cmd.exe, curl, wget, python, nc); unexpected execSync or spawn calls visible in process trees.
  • File System: New or modified files in the n8n working directory or temp directories; unexpected scripts, cron jobs, or scheduled tasks created by the n8n service account; web shells or backdoors dropped on the host.
  • Workflow Artifacts: Workflows containing expressions with patterns such as constructor.constructor, process.mainModule, require('child_process'), or execSync/exec within parameter fields (GitHub Advisory, Pillar Security Blog).

Mitigation and workarounds

The primary remediation is to upgrade n8n to version 1.123.17 (for the 1.x branch) or 2.5.2 (for the 2.x branch), which contain the patches for this vulnerability (GitHub Advisory). If immediate upgrading is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and deploy n8n in a hardened environment with restricted OS privileges and limited network access. These workarounds do not fully remediate the risk and should only be used as short-term measures. Additionally, monitoring workflow parameter inputs for suspicious expression patterns and reviewing audit logs for unauthorized workflow modifications are recommended (n8n Security Advisory).

Community reactions

The vulnerability received widespread coverage from major security outlets including BleepingComputer, The Hacker News, SecurityWeek, The Register, and TechRadar within hours of disclosure (BleepingComputer, The Hacker News, SecurityWeek, The Register). National CERTs including Canada's CCCS (AV26-091), Singapore's CSA (AL-2026-011), and Belgium's CCB issued advisories, and Germany's BSI also flagged the issue via the n8n community forum. Security researchers from Pillar Security, SOCRadar, Field Effect, and OPSWAT published detailed technical analyses. Community discussion was active on Reddit (r/netsec, r/blueteamsec, r/crowdstrike) and Mastodon/Bluesky, with defenders sharing hunting queries and IOCs. VulnCheck published a blog noting the vulnerability's addition to CISA KEV (VulnCheck).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103493HIGH8.1
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103494MEDIUM6.6
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026
CVE-2026-103495MEDIUM4.3
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management