Protection Mechanism Failure in n8n - CVE-2026-27495

 

Protection Mechanism Failure in n8n - CVE-2026-27495

Published: March 13, 2026


Vulnerability identifier: #VU124007
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27495
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A remote user with permission to create or modify workflows can bypass the JavaScript Task Runner sandbox and execute arbitrary code outside the sandbox boundary.


Affected software

n8n

How to mitigate CVE-2026-27495

Install updates from vendor's website.

n8n - addressed in versions 1.123.22, 2.9.3, 2.10.1

External References

Related Security Bulletins