CVE-2026-27494: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27494 is a Python Code Node sandbox escape vulnerability in n8n, an open-source workflow automation platform, formally titled "n8n has Arbitrary File Read via Python Code Node Sandbox Escape." An authenticated user with workflow creation or modification permissions can exploit insufficient sandbox restrictions to exfiltrate file contents or achieve remote code execution (RCE) on the host. Affected versions include all releases before 1.123.22, versions 2.0.0 through 2.9.3 (exclusive), and versions 2.10.0 through 2.10.1 (exclusive). The vulnerability was published on February 25, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 9.9 (Critical) and a CVSS v4.0 base score of 7.1 (High) per the GitHub Advisory Database (Github Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere): the Python Code node's sandbox did not sufficiently restrict access to certain built-in Python objects, allowing an attacker to traverse sandbox boundaries (Github Advisory). Exploitation requires network access and low-privilege authenticated credentials (e.g., a standard user account with workflow editing rights), with no user interaction needed. An attacker crafts a malicious Python script within a workflow's Code node that leverages unrestricted built-in Python introspection (e.g., __class__, __subclasses__, or similar object traversal techniques) to break out of the sandbox and access the underlying file system or execute arbitrary OS commands. The vulnerability is only exploitable when Task Runners are enabled via the N8N_RUNNERS_ENABLED=true environment variable (n8n Security Advisory).

Impact

On instances using internal Task Runners (the default runner mode), successful exploitation can result in full compromise of the n8n host, including arbitrary file read, remote code execution, and complete loss of confidentiality, integrity, and availability (n8n Security Advisory). On instances using external Task Runners, an attacker may gain access to or disrupt other tasks executing on the shared Task Runner, potentially enabling lateral movement to other workflows or data. Sensitive files such as credentials, environment variables, and configuration files stored on the host are at direct risk of exfiltration. Reports indicate over 24,700 n8n instances may be exposed to this risk (The Daily Tech Feed).

Exploitability

As of the time of publication, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.032% (0.000320), placing it in the 26th percentile for exploitation probability within 30 days. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researchers MarcoPoloPie and Nico-Posada (n8n Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify internet-facing n8n instances running vulnerable versions (< 1.123.22, 2.0.0–2.9.3, or 2.10.0) using tools like Shodan or Censys, searching for n8n login pages or API endpoints.
  2. Authentication: Log in to the n8n instance using a valid account that has permission to create or modify workflows (e.g., a standard user or compromised credentials).
  3. Create or modify a workflow: Navigate to the workflow editor and add or modify a Python Code node within an existing or new workflow.
  4. Craft sandbox escape payload: Insert a Python script that leverages unrestricted built-in object access to escape the sandbox — for example, using Python's object introspection chain (().__class__.__bases__[0].__subclasses__()) to locate and invoke OS-level functions such as subprocess.Popen or os.system.
  5. Exfiltrate files or execute commands: Use the escaped sandbox context to read sensitive files (e.g., /etc/passwd, .env, n8n credential files) or execute arbitrary OS commands, establishing a reverse shell or exfiltrating data to an attacker-controlled server.
  6. Lateral movement (if applicable): On internal Task Runner instances, leverage full host access to pivot to other systems on the network or escalate privileges (n8n Security Advisory).

Indicators of compromise

  • Logs: n8n workflow execution logs showing Python Code node executions by non-administrative users, especially workflows recently created or modified; unexpected errors or stack traces related to Python built-in object access in n8n task runner logs.
  • File System: Unexpected access or modification of sensitive files (e.g., .env, config.json, /etc/passwd, SSH keys) by the n8n process user; presence of new scripts or binaries in the n8n working directory or temp directories.
  • Process: Unusual child processes spawned by the n8n Node.js process or Task Runner process (e.g., bash, sh, curl, wget, python3) that are not part of normal n8n operation; unexpected outbound network connections from the n8n host to external IPs.
  • Network: Outbound connections from the n8n server to unfamiliar external IP addresses or domains, particularly on non-standard ports, following workflow execution events.

Mitigation and workarounds

n8n released patched versions on February 25, 2026: 1.123.22, 2.9.3, and 2.10.1. All users should upgrade to one of these versions or later as the primary remediation (n8n Security Advisory, n8n Release 1.123.22, n8n Release 2.10.1). If immediate upgrade is not possible, administrators should: (1) restrict workflow creation and editing permissions to fully trusted users only, and (2) disable the Code node by adding n8n-nodes-base.code to the NODES_EXCLUDE environment variable. Additionally, disable Task Runners if not required by setting N8N_RUNNERS_ENABLED=false. These workarounds do not fully eliminate the risk and should only be used as short-term measures.

Community reactions

n8n published an official security bulletin and community forum post on February 25, 2026, disclosing the vulnerability and directing users to upgrade immediately (n8n Blog, n8n Community). The vulnerability was picked up by threat intelligence aggregators including SentinelOne, CIRCL, and INCIBE shortly after disclosure. Media coverage highlighted the potential exposure of over 24,700 n8n instances to RCE risk, drawing attention to the broad attack surface of self-hosted workflow automation platforms (The Daily Tech Feed).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management