Protection Mechanism Failure in n8n - CVE-2026-27495
Published: March 13, 2026
Vulnerability identifier: #VU124007
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-27495
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote user to bypass implemented security restrictions.
The vulnerability exists due to insufficient implementation of security measures. A remote user with permission to create or modify workflows can bypass the JavaScript Task Runner sandbox and execute arbitrary code outside the sandbox boundary.
Affected software
n8n
How to mitigate CVE-2026-27495
Install updates from vendor's website.
n8n - addressed in versions 1.123.22, 2.9.3, 2.10.1