CVE-2026-27495: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27495 is a sandbox escape vulnerability in n8n's JavaScript Task Runner, allowing authenticated users with workflow creation or modification permissions to execute arbitrary code outside the sandbox boundary. Disclosed on February 25, 2026, it affects n8n versions prior to 1.123.22, versions 2.0.0–2.9.3, and versions 2.10.0–2.10.1 for the Node.js npm package. The vulnerability carries a CVSS v4.0 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.9 (Critical). Exploitation requires Task Runners to be enabled via N8N_RUNNERS_ENABLED=true (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): n8n's JavaScript Task Runner sandbox fails to properly neutralize or restrict externally-influenced input, allowing crafted JavaScript code to break out of the intended sandbox boundary. An attacker with a low-privilege authenticated account and workflow creation/modification rights can craft a malicious workflow containing JavaScript that escapes the Task Runner sandbox and executes arbitrary code on the underlying host or Task Runner process. No user interaction is required, and the attack is conducted over the network with low complexity. The vulnerability was discovered and reported by researcher c0rydoras (GitHub Advisory, n8n Security Advisory).

Impact

On instances using the default internal Task Runner mode, successful exploitation results in full compromise of the n8n host system — complete loss of confidentiality, integrity, and availability, including access to stored credentials, workflow data, and connected service secrets. On instances using external Task Runners, the attacker can access or disrupt other tasks running on the shared Task Runner infrastructure, potentially enabling lateral movement to connected systems. The scope change (CVSS S:C) reflects that the impact extends beyond the vulnerable component itself to subsequent systems (GitHub Advisory, n8n Security Advisory).

Exploitability

As of the time of disclosure, no public proof-of-concept exploit code has been identified, and there is no confirmed evidence of in-the-wild exploitation (GitHub Advisory). The EPSS score is approximately 0.104% (28th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No specific threat actor attribution has been reported. Exploitation requires an authenticated account with workflow permissions and Task Runners enabled (N8N_RUNNERS_ENABLED=true), which limits the attack surface compared to unauthenticated vulnerabilities (n8n Security Advisory).

Exploitation steps

  1. Reconnaissance: Identify n8n instances with Task Runners enabled (N8N_RUNNERS_ENABLED=true) running vulnerable versions (< 1.123.22, 2.0.0–2.9.3, or 2.10.0). Use Shodan, Censys, or similar tools to locate internet-facing n8n deployments.
  2. Obtain authenticated access: Acquire credentials for an account with workflow creation or modification permissions — this could be via phishing, credential stuffing, or a low-privilege account on a multi-tenant instance.
  3. Create or modify a malicious workflow: Log in to the n8n interface and create or edit a workflow that includes a JavaScript "Code" node (or equivalent node type that invokes the JavaScript Task Runner).
  4. Inject sandbox escape payload: Craft JavaScript code within the workflow node that exploits the insufficient sandbox restrictions to break out of the Task Runner boundary — for example, using Node.js built-in module access or prototype chain manipulation to reach the host OS context.
  5. Execute arbitrary code: Trigger the workflow execution. The malicious JavaScript escapes the sandbox and executes arbitrary commands on the n8n host (internal runner mode) or the shared Task Runner process (external runner mode), enabling reverse shell establishment, credential harvesting, or further lateral movement (n8n Security Advisory, GitHub Advisory).

Indicators of compromise

  • Logs: n8n application logs showing workflow executions by low-privilege users that invoke JavaScript Task Runner nodes with unusual or obfuscated code content; unexpected errors or stack traces from the Task Runner process indicating sandbox boundary violations.
  • Process: Unusual child processes spawned by the n8n Task Runner process (e.g., sh, bash, cmd.exe, curl, wget, python, node) that are not part of normal workflow execution.
  • Network: Unexpected outbound connections from the n8n host or Task Runner container to external IP addresses, particularly on non-standard ports; DNS lookups for unfamiliar domains initiated by the n8n process.
  • File System: New or modified files in the n8n installation directory or system directories created by the n8n service account; presence of web shells, reverse shell scripts, or persistence mechanisms (cron jobs, scheduled tasks) added under the n8n user context.
  • Workflow Activity: Workflows created or modified by non-admin users containing JavaScript Code nodes with encoded, obfuscated, or unusually complex payloads; workflow execution logs showing abnormal runtime durations or errors in the Task Runner component.

Mitigation and workarounds

Upgrade n8n to one of the patched versions: 1.123.22, 2.9.3, or 2.10.1, all released on February 25, 2026 (n8n Release 1.123.22, n8n Release 2.9.3, n8n Release 2.10.1). If immediate upgrade is not possible, apply the following temporary mitigations in order of priority:

  1. Restrict permissions: Limit workflow creation and editing to fully trusted users only.
  2. Use external runner mode: Set N8N_RUNNERS_MODE=external to confine potential exploitation to the Task Runner process rather than the full host.

Note that these workarounds do not fully eliminate the risk and should only be used as short-term measures until patching is complete (n8n Security Advisory).

Community reactions

n8n published a security blog post and community forum bulletin on February 25, 2026 announcing the patches and advisories (n8n Blog, n8n Community). Heise Online covered the vulnerability, describing it as a critical code injection flaw threatening n8n workflow servers (Heise Online). The Belgian Centre for Cybersecurity (CCB) issued a warning urging immediate patching (CCB Advisory). The Shadowserver Foundation noted the vulnerability on social media, and The Hacker News published coverage in early March 2026 highlighting the RCE risk and credential exposure potential (The Hacker News). SecurityOnline.info described it as part of a set of "triple 9.4 severity" RCE flaws threatening n8n workflow servers.

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management