Improper access control in n8n - #VU132383
Published: May 27, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the Python Code Node sandbox when executing user-defined Python workflows. A remote user can create or modify a workflow containing a Python Code Node to execute arbitrary code.
Only instances with the Python Task Runner enabled are vulnerable.