
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27577 is an expression sandbox escape vulnerability in the n8n open-source workflow automation platform, classified as "Expression Sandbox Escape Leading to RCE." It affects n8n versions prior to 1.123.22, versions 2.0.0 through 2.9.3 (exclusive), and versions 2.10.0 through 2.10.1 (exclusive). The vulnerability was disclosed on February 25, 2026, following the earlier related vulnerability CVE-2025-68613. It carries a CVSS v4 base score of 9.4 (Critical) and a CVSS v3.1 base score of 9.9 (Critical) (Github Advisory, n8n Advisory).
The root cause is classified as CWE-94 (Improper Control of Generation of Code / Code Injection): n8n's expression evaluation engine does not sufficiently isolate user-supplied expressions from the underlying Node.js runtime, allowing crafted inputs to escape the intended sandbox. An authenticated attacker with workflow creation or modification permissions can embed malicious expressions in workflow parameters — including fields processed by the JavaScript or Python task runners — that, when evaluated, break out of the sandboxed context and execute arbitrary system commands with the privileges of the n8n process. Patch commits reveal fixes including blocking additional dangerous Python introspection attributes (e.g., __objclass__) in the task runner's allowlist, sanitizing user inputs in ChatTrigger templates, and hardening webhook authentication logic (n8n Advisory, Patch Commit 1, Patch Commit 2). This vulnerability is a follow-on to CVE-2025-68613, indicating that the original sandbox hardening was incomplete (Github Advisory).
Successful exploitation allows an authenticated attacker to execute arbitrary system commands on the host running n8n with the privileges of the n8n process, potentially leading to full system compromise. This includes unauthorized access to sensitive data (including stored credentials and workflow secrets), modification or deletion of workflows and system files, disruption of service, and lateral movement to other systems accessible from the n8n host. The scope change (CVSS S:C) reflects that impact extends beyond the n8n application itself to the underlying host and potentially connected systems (n8n Advisory, Github Advisory).
CISA has flagged this vulnerability as actively exploited in the wild, with reports indicating approximately 24,700 internet-exposed n8n instances at risk (The Hacker News, undercodenews). The vulnerability requires only low privileges (an authenticated user account) and no user interaction, making it straightforward to weaponize. The EPSS score is approximately 0.175% (39th percentile) per the GitHub Advisory Database, though active exploitation has been confirmed (Github Advisory). Pillar Security published research describing a related zero-click unauthenticated RCE attack path via n8n's contact form/ChatTrigger, further expanding the attack surface (Pillar Security). No specific threat actor attribution has been publicly reported.
{{ }} expression syntax).__objclass__ and similar Python introspection attributes), payloads may leverage prototype chain traversal or Python task runner introspection to reach os.system() or equivalent. Example conceptual payload: {{ $evaluateExpression('<sandbox_escape_payload_reaching_child_process.exec>') }}.__objclass__, __class__, child_process, os.system, or encoded payloads); repeated workflow execution errors related to expression evaluation.sh, bash, cmd.exe, curl, wget, python); unusual process trees originating from the n8n service account.Upgrade n8n to one of the patched versions: 1.123.22, 2.9.3, or 2.10.1 (or any later release). These versions contain fixes for all known expression sandbox escape vulnerabilities including CVE-2026-27577 and its predecessor CVE-2025-68613. If immediate upgrade is not possible, apply the following temporary mitigations: (1) restrict workflow creation and editing permissions to fully trusted users only; (2) deploy n8n in a hardened environment with restricted OS-level privileges (e.g., run as a non-root user with minimal permissions) and limit network access from the n8n host. Note that these workarounds do not fully eliminate the risk and should only be used as short-term measures (Github Advisory, n8n Advisory).
The n8n team published a security blog post and community forum bulletin on February 25, 2026, the same day as disclosure, demonstrating rapid vendor response (n8n Blog, n8n Community). CISA subsequently added the vulnerability to its Known Exploited Vulnerabilities catalog and ordered federal agencies to patch, generating significant media coverage from outlets including The Hacker News, Heise, SecurityWeek, and Infosecurity Magazine (The Hacker News, SecurityWeek). Pillar Security published notable research detailing a zero-click unauthenticated RCE path via n8n's ChatTrigger contact form, which attracted significant community attention on Reddit and security forums (Pillar Security). Belgium's CCB and the Isle of Man's CSC also issued advisories urging immediate patching (CCB Belgium).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."