CVE-2026-27577: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-27577 is an expression sandbox escape vulnerability in the n8n open-source workflow automation platform, classified as "Expression Sandbox Escape Leading to RCE." It affects n8n versions prior to 1.123.22, versions 2.0.0 through 2.9.3 (exclusive), and versions 2.10.0 through 2.10.1 (exclusive). The vulnerability was disclosed on February 25, 2026, following the earlier related vulnerability CVE-2025-68613. It carries a CVSS v4 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, n8n Advisory).

Technical details

The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): n8n's expression evaluation engine does not sufficiently isolate user-supplied expressions from the underlying Node.js runtime, allowing crafted inputs to escape the intended sandbox. An authenticated attacker with workflow creation or modification permissions can embed malicious expressions in workflow parameters — including fields processed by the JavaScript or Python task runners — that, when evaluated, break out of the sandboxed context and execute arbitrary system commands with the privileges of the n8n process. Patch commits reveal fixes including blocking additional dangerous Python introspection attributes (e.g., __objclass__) in the task runner's allowlist, sanitizing user inputs in ChatTrigger templates, and hardening webhook authentication logic (n8n Advisory, Patch Commit 1, Patch Commit 2). This vulnerability is a follow-on to CVE-2025-68613, indicating that the original sandbox hardening was incomplete (Github Advisory).

Impact

Successful exploitation allows an authenticated attacker to execute arbitrary system commands on the host running n8n with the privileges of the n8n process, potentially leading to full system compromise. This includes unauthorized access to sensitive data (including stored credentials and workflow secrets), modification or deletion of workflows and system files, disruption of service, and lateral movement to other systems accessible from the n8n host. The scope change (CVSS S:C) reflects that impact extends beyond the n8n application itself to the underlying host and potentially connected systems (n8n Advisory, Github Advisory).

Exploitability

CISA has flagged this vulnerability as actively exploited in the wild, with reports indicating approximately 24,700 internet-exposed n8n instances at risk (The Hacker News, undercodenews). The vulnerability requires only low privileges (an authenticated user account) and no user interaction, making it straightforward to weaponize. The EPSS score is approximately 0.175% (39th percentile) per the GitHub Advisory Database, though active exploitation has been confirmed (Github Advisory). Pillar Security published research describing a related zero-click unauthenticated RCE attack path via n8n's contact form/ChatTrigger, further expanding the attack surface (Pillar Security). No specific threat actor attribution has been publicly reported.

Exploitation steps

  1. Reconnaissance: Identify internet-facing n8n instances using tools like Shodan or Censys, filtering for the n8n web interface (default port 5678). Confirm the version is vulnerable (< 1.123.22, 2.0.0–2.9.3, or 2.10.0–2.10.1).
  2. Obtain authentication: Acquire valid n8n credentials — either through credential stuffing, phishing, or by registering a low-privilege account if self-registration is enabled.
  3. Create or modify a workflow: Log in to the n8n interface and create a new workflow (or modify an existing one) that includes a node with an expression-evaluated parameter field (e.g., a Function node, Set node, or any node supporting {{ }} expression syntax).
  4. Inject malicious expression: Craft a payload that escapes the expression sandbox and executes a system command. Based on the patch context (blocking __objclass__ and similar Python introspection attributes), payloads may leverage prototype chain traversal or Python task runner introspection to reach os.system() or equivalent. Example conceptual payload: {{ $evaluateExpression('<sandbox_escape_payload_reaching_child_process.exec>') }}.
  5. Trigger workflow execution: Activate the workflow manually or via a webhook trigger to cause the malicious expression to be evaluated server-side.
  6. Achieve RCE: The injected expression executes arbitrary OS commands as the n8n process user, enabling reverse shell establishment, credential exfiltration, or further lateral movement (n8n Advisory, Pillar Security).

Indicators of compromise

  • Network: Unusual outbound connections from the n8n host to unknown external IPs or domains, particularly on non-standard ports (potential reverse shell or C2 traffic); unexpected DNS lookups from the n8n process.
  • Logs: n8n execution logs showing workflow runs with anomalous expression content (e.g., references to __objclass__, __class__, child_process, os.system, or encoded payloads); repeated workflow execution errors related to expression evaluation.
  • Process: Unexpected child processes spawned by the n8n Node.js process (e.g., sh, bash, cmd.exe, curl, wget, python); unusual process trees originating from the n8n service account.
  • File System: New or modified files in the n8n installation directory or temp directories; unexpected cron jobs, scheduled tasks, or startup scripts created by the n8n service account; web shells or backdoors placed on the host.
  • Authentication: New user accounts created in n8n; unexpected workflow creation or modification events in the n8n audit log, especially by low-privilege accounts (n8n Advisory, The Hacker News).

Mitigation and workarounds

Upgrade n8n to one of the patched versions: 1.123.22, 2.9.3, or 2.10.1 (or any later release). These versions contain fixes for all known expression sandbox escape vulnerabilities including CVE-2026-27577 and its predecessor CVE-2025-68613. If immediate upgrade is not possible, apply the following temporary mitigations: (1) restrict workflow creation and editing permissions to fully trusted users only; (2) deploy n8n in a hardened environment with restricted OS-level privileges (e.g., run as a non-root user with minimal permissions) and limit network access from the n8n host. Note that these workarounds do not fully eliminate the risk and should only be used as short-term measures (Github Advisory, n8n Advisory).

Community reactions

The n8n team published a security blog post and community forum bulletin on February 25, 2026, the same day as disclosure, demonstrating rapid vendor response (n8n Blog, n8n Community). CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch, generating significant media coverage from outlets including The Hacker News, Heise, SecurityWeek, and Infosecurity Magazine (The Hacker News, SecurityWeek). Pillar Security published notable research detailing a zero-click unauthenticated RCE path via n8n's ChatTrigger contact form, which attracted significant community attention on Reddit and security forums (Pillar Security). Belgium's CCB and the Isle of Man's CSC also issued advisories urging immediate patching (CCB Belgium).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management