Code Injection in n8n - CVE-2026-42234

 

Code Injection in n8n - CVE-2026-42234

Published: April 23, 2026


Vulnerability identifier: #VU127225
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42234
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code on the task runner container.

The vulnerability exists due to improper control of code generation in the Python Code Node when creating or modifying workflows containing Python code. A remote user can craft a malicious workflow to execute arbitrary code on the task runner container.

This issue only affects instances where the Python Task Runner is enabled.


Affected software

n8n

How to mitigate CVE-2026-42234

Install security update from vendor's website.

n8n - addressed in versions 1.123.32, 2.17.4, 2.18.1

External References

Related Security Bulletins