
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27494 is a Python Code Node sandbox escape vulnerability in n8n, an open-source workflow automation platform, formally titled "n8n has Arbitrary File Read via Python Code Node Sandbox Escape." An authenticated user with workflow creation or modification permissions can exploit insufficient sandbox restrictions to exfiltrate file contents or achieve remote code execution (RCE) on the host. Affected versions include all releases before 1.123.22, versions 2.0.0 through 2.9.3 (exclusive), and versions 2.10.0 through 2.10.1 (exclusive). The vulnerability was published on February 25, 2026, with patches released the same day. It carries a CVSS v3.1 base score of 9.9 (Critical) and a CVSS v4.0 base score of 7.1 (High) per the GitHub Advisory Database (Github Advisory, n8n Security Advisory).
The root cause is classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere): the Python Code node's sandbox did not sufficiently restrict access to certain built-in Python objects, allowing an attacker to traverse sandbox boundaries (Github Advisory). Exploitation requires network access and low-privilege authenticated credentials (e.g., a standard user account with workflow editing rights), with no user interaction needed. An attacker crafts a malicious Python script within a workflow's Code node that leverages unrestricted built-in Python introspection (e.g., __class__, __subclasses__, or similar object traversal techniques) to break out of the sandbox and access the underlying file system or execute arbitrary OS commands. The vulnerability is only exploitable when Task Runners are enabled via the N8N_RUNNERS_ENABLED=true environment variable (n8n Security Advisory).
On instances using internal Task Runners (the default runner mode), successful exploitation can result in full compromise of the n8n host, including arbitrary file read, remote code execution, and complete loss of confidentiality, integrity, and availability (n8n Security Advisory). On instances using external Task Runners, an attacker may gain access to or disrupt other tasks executing on the shared Task Runner, potentially enabling lateral movement to other workflows or data. Sensitive files such as credentials, environment variables, and configuration files stored on the host are at direct risk of exfiltration. Reports indicate over 24,700 n8n instances may be exposed to this risk (The Daily Tech Feed).
As of the time of publication, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Github Advisory). The EPSS score is approximately 0.032% (0.000320), placing it in the 26th percentile for exploitation probability within 30 days. No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The vulnerability was reported by researchers MarcoPoloPie and Nico-Posada (n8n Security Advisory).
().__class__.__bases__[0].__subclasses__()) to locate and invoke OS-level functions such as subprocess.Popen or os.system./etc/passwd, .env, n8n credential files) or execute arbitrary OS commands, establishing a reverse shell or exfiltrating data to an attacker-controlled server..env, config.json, /etc/passwd, SSH keys) by the n8n process user; presence of new scripts or binaries in the n8n working directory or temp directories.bash, sh, curl, wget, python3) that are not part of normal n8n operation; unexpected outbound network connections from the n8n host to external IPs.n8n released patched versions on February 25, 2026: 1.123.22, 2.9.3, and 2.10.1. All users should upgrade to one of these versions or later as the primary remediation (n8n Security Advisory, n8n Release 1.123.22, n8n Release 2.10.1). If immediate upgrade is not possible, administrators should: (1) restrict workflow creation and editing permissions to fully trusted users only, and (2) disable the Code node by adding n8n-nodes-base.code to the NODES_EXCLUDE environment variable. Additionally, disable Task Runners if not required by setting N8N_RUNNERS_ENABLED=false. These workarounds do not fully eliminate the risk and should only be used as short-term measures.
n8n published an official security bulletin and community forum post on February 25, 2026, disclosing the vulnerability and directing users to upgrade immediately (n8n Blog, n8n Community). The vulnerability was picked up by threat intelligence aggregators including SentinelOne, CIRCL, and INCIBE shortly after disclosure. Media coverage highlighted the potential exposure of over 24,700 n8n instances to RCE risk, drawing attention to the broad attack surface of self-hosted workflow automation platforms (The Daily Tech Feed).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."