CVE-2026-25049
n8n is an open source workflow automation platform. Prior to versions 1.123.17 and 2.5.2, an authenticated user with permission to create or modify workflows could abuse crafted expressions in workflow parameters to trigger unintended system command execution on the host running n8n. This issue has been patched in versions 1.123.17 and 2.5.2.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 9.4
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
- EPSS probability
- 1.45%
- CWE
- CWE-913
- Published
- 2026-02-04
- Last modified
- 2026-03-12
Affected products
- n8n-io n8n
- n8n-io n8n
Weakness type
Related vulnerabilities
- CVE-2026-41870 — Apache Nutch: Unauthenticated remote code execution (RCE) via JEXL injection in Nutch Server (Nutch REST API)
- CVE-2026-65181 — Apache Impala: RCE via External Data Source Class Loading
- CVE-2026-85408 — Eleveo Quality Management Conversation events dynamically-determined object attributes
- CVE-2026-84430 — gouguoa edit_personal Endpoint Index.php update dynamically-determined object attributes
- CVE-2026-48105 — Arc Enterprise cluster FSM applyRegisterFile accepts arbitrary file paths without validation, enabling cluster-wide path-traversal worm primitive
- CVE-2026-76023 — Improper resource control in Linux Toolkit Theming in Google Chrome prior to 151.0.7922.173 allowed...
- CVE-2026-71470 — Acm-search-v2-rhel9: search-v2-operator: search cr imageoverride/arguments/envvar flow unsanitized into pods running impersonating sa
- CVE-2026-47698 — vm2: Sandbox Breakout Using Dangerous Host Proto Mutators