CVE-2026-27496: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27496 is an in-process memory disclosure vulnerability in n8n, an open-source workflow automation platform, affecting its JavaScript Task Runner component. An authenticated user with workflow creation or modification permissions can allocate uninitialized memory buffers that may contain residual Node.js process data — including secrets, tokens, and prior request data — leading to sensitive information disclosure. The vulnerability was published on March 25, 2026, and affects n8n versions prior to 1.123.22, versions 2.0.0-rc.0 through 2.9.3 (exclusive), and version 2.10.0. It carries a CVSS v3.1 score of 6.5 (Medium) and a CVSS v4.0 score of 7.1 (High) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-908 (Use of Uninitialized Resource): the JavaScript Task Runner in n8n allows authenticated users to allocate Buffer objects in Node.js without proper initialization, a known pitfall where Buffer.allocUnsafe() or similar APIs can expose previously used memory regions. Because Node.js reuses heap memory across operations within the same process, these uninitialized buffers may contain residual data from prior requests, workflow executions, secrets, or authentication tokens. Exploitation requires the Task Runner feature to be enabled (N8N_RUNNERS_ENABLED=true), and the attacker must have authenticated access with workflow creation or editing privileges. The vulnerability was reported by researcher c0rydoras (GitHub Advisory, n8n Security Advisory).

Impact

Successful exploitation results in high confidentiality impact with no integrity or availability impact. An attacker can read arbitrary in-process memory from the n8n Node.js process, potentially exposing API keys, authentication tokens, secrets stored in environment variables, and data from other users' workflow executions processed by the same instance. In external runner mode (N8N_RUNNERS_MODE=external), the exposure is limited to data within the isolated runner process, reducing but not eliminating the risk of cross-tenant or cross-workflow data leakage (GitHub Advisory, n8n Security Advisory).

Exploitability

No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported as of the time of this report. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.032–0.041% (13th percentile), indicating a low near-term exploitation probability. Exploitation requires authenticated access with workflow editing privileges and the Task Runner feature to be explicitly enabled, which limits the attack surface (GitHub Advisory).

Exploitation steps

  1. Gain authenticated access: Obtain credentials for an n8n account with workflow creation or editing permissions — this could be via phishing, credential stuffing, or a legitimate low-privilege account on a shared n8n instance.
  2. Verify Task Runner is enabled: Confirm that N8N_RUNNERS_ENABLED=true is set on the target n8n instance, as the vulnerability only exists when this feature is active.
  3. Create or modify a workflow: Navigate to the n8n workflow editor and create or open an existing workflow that uses the JavaScript (Code) node, which leverages the Task Runner.
  4. Craft a malicious JavaScript payload: Write a JavaScript snippet that allocates an uninitialized Buffer of a specified size (e.g., Buffer.allocUnsafe(4096)) and returns or exfiltrates its contents, exploiting Node.js memory reuse behavior.
  5. Execute the workflow: Run the workflow to trigger the Task Runner, causing the uninitialized buffer to be populated with residual in-process memory.
  6. Exfiltrate disclosed data: Capture the buffer output (e.g., via HTTP request node, workflow output, or logging) and analyze it for secrets, tokens, or other sensitive data from prior process operations (GitHub Advisory, n8n Security Advisory).

Indicators of compromise

  • Logs: n8n workflow execution logs showing repeated execution of JavaScript Code nodes with short, unusual scripts focused on Buffer allocation (e.g., Buffer.allocUnsafe, Buffer.alloc with no initialization); unexpected workflow executions by low-privilege users.
  • Network: Outbound HTTP requests from n8n workflows to external or unexpected endpoints carrying large binary or base64-encoded payloads, potentially containing exfiltrated memory contents.
  • Application Behavior: Unusual patterns of workflow creation or modification by accounts that do not typically author workflows; workflows with minimal logic but HTTP output nodes pointing to attacker-controlled infrastructure.
  • Process: Node.js process logs indicating high-frequency Task Runner invocations from a single user account in a short time window.

Mitigation and workarounds

Patches are available in n8n versions 1.123.22, 2.9.3, and 2.10.1 — users should upgrade to one of these versions or later as the primary remediation. If immediate upgrade is not possible, administrators should restrict workflow creation and editing permissions to fully trusted users only, and/or switch to external runner mode (N8N_RUNNERS_MODE=external) to isolate the runner process and limit the scope of any memory disclosure. Note that these workarounds do not fully eliminate the risk and are intended only as short-term measures (n8n Security Advisory, GitHub Advisory).

Community reactions

The advisory was published by n8n maintainer "Jubke" on GitHub on March 25, 2026, with credit to researcher c0rydoras for the report. No significant broader media coverage, vendor statements beyond the official advisory, or notable community commentary have been identified at this time (n8n Security Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management