#VU122481 Improper Control of Dynamically-Managed Code Resources in n8n - CVE-2026-25049
Published: February 9, 2026
n8n
n8n
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists due to an incomplete fix in the expression evaluation for #VU120269 (CVE-2025-68613). A remote user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n.