
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-25049 is an expression sandbox escape vulnerability in n8n, an open-source workflow automation platform, that allows authenticated users with workflow creation or modification permissions to execute arbitrary system commands on the host running n8n. Disclosed on February 4, 2026, it affects all n8n versions prior to 1.123.17 (1.x branch) and prior to 2.5.2 (2.x branch, starting from 2.0.0). The vulnerability is classified as Critical with a CVSS v4.0 base score of 9.4 and a CVSS v3.1 base score of 9.9 (GitHub Advisory, n8n Security Advisory). This issue follows and extends CVE-2025-68613, a prior expression evaluation vulnerability in the same platform.
The root cause is classified as CWE-913 (Improper Control of Dynamically-Managed Code Resources), specifically a failure to properly sandbox expression evaluation within n8n workflow parameters (GitHub Advisory). An attacker crafts malicious expressions embedded in workflow node parameters that escape the intended expression evaluation sandbox, causing the underlying Node.js runtime to execute arbitrary operating system commands. Exploitation requires only low-level authenticated access (e.g., a standard user account with workflow edit permissions) and no user interaction, making it highly accessible to insider threats or compromised accounts. Public proof-of-concept code demonstrating the sandbox escape technique is available at PoC GitHub, and additional technical analysis has been published by multiple security researchers (Pillar Security Blog, SOCRadar).
Successful exploitation grants an attacker arbitrary command execution on the host operating system running n8n, with the privileges of the n8n service account. This can lead to complete system compromise, unauthorized access to sensitive data stored on the host or accessible via the network, data manipulation, service disruption, and lateral movement within the broader infrastructure (GitHub Advisory, Pillar Security Blog). Given that n8n is widely deployed in enterprise AI and automation environments — with hundreds of thousands of instances reported — the potential blast radius is significant (eSecurity Planet). The CVSS v4.0 score reflects high impact across confidentiality, integrity, and availability for both the vulnerable and subsequent systems.
A public proof-of-concept exploit is available on GitHub (PoC GitHub), and active exploitation in the wild has been reported by multiple sources including BleepingComputer (BleepingComputer). CISA added this vulnerability to its Known Exploited Vulnerabilities (KEV) catalog in March 2026, ordering federal agencies to patch (The Register). The EPSS score is approximately 0.026% (low automated exploitation probability), but real-world exploitation has been confirmed. Detection signatures have been published by Qualys (IDs: 733668, 5007426, 530913) and Nessus (ID: 298984), and a Nuclei template pull request was submitted to ProjectDiscovery (Feedly).
{{ }}), craft a payload that escapes the expression sandbox. Based on the sandbox escape technique (CWE-913), this involves abusing JavaScript prototype chain access or constructor references to reach Node.js built-ins such as process or child_process. Example pattern: {{ $evaluateExpression('...constructor.constructor("return process")().mainModule.require("child_process").execSync("id")') }}.sh, bash, cmd.exe, curl, wget, python, nc); unexpected execSync or spawn calls visible in process trees.constructor.constructor, process.mainModule, require('child_process'), or execSync/exec within parameter fields (GitHub Advisory, Pillar Security Blog).The primary remediation is to upgrade n8n to version 1.123.17 (for the 1.x branch) or 2.5.2 (for the 2.x branch), which contain the patches for this vulnerability (GitHub Advisory). If immediate upgrading is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and deploy n8n in a hardened environment with restricted OS privileges and limited network access. These workarounds do not fully remediate the risk and should only be used as short-term measures. Additionally, monitoring workflow parameter inputs for suspicious expression patterns and reviewing audit logs for unauthorized workflow modifications are recommended (n8n Security Advisory).
The vulnerability received widespread coverage from major security outlets including BleepingComputer, The Hacker News, SecurityWeek, The Register, and TechRadar within hours of disclosure (BleepingComputer, The Hacker News, SecurityWeek, The Register). National CERTs including Canada's CCCS (AV26-091), Singapore's CSA (AL-2026-011), and Belgium's CCB issued advisories, and Germany's BSI also flagged the issue via the n8n community forum. Security researchers from Pillar Security, SOCRadar, Field Effect, and OPSWAT published detailed technical analyses. Community discussion was active on Reddit (r/netsec, r/blueteamsec, r/crowdstrike) and Mastodon/Bluesky, with defenders sharing hunting queries and IOCs. VulnCheck published a blog noting the vulnerability's addition to CISA KEV (VulnCheck).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."