Threat reportVulnerabilityTL-2026-0094
n8n Multi-CVE Vulnerability Cascade — Expression Sandbox Escape, Pyodide RCE, Arbitrary File Write, Command Injection (9 CVEs, 2× CVSS 10.0)
n8n Multi-CVE Vulnerability Cascade (TL-2026-0094) is a critical-severity software vulnerability, first published 2026-02-04. It has no confirmed attribution, references 9 CVEs (CVE-2025-68613, CVE-2026-25049, CVE-2025-68668), maps to 25 MITRE ATT&CK techniques (T1005, T1053.003, T1059.004), and is covered by 9 detection rules and 32 indicators of compromise.
- Severity
- CRITICALAssessed severity
- CVEs
- 9Referenced vulnerabilities
- Techniques
- 25MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 32Indicators of compromise
Key facts for TL-2026-0094
- Threat ID
- TL-2026-0094
- Severity
- CRITICAL
- Status
- ACTIVE
- Category
- VULNERABILITY
- First published
- Last reviewed
- Attribution confidence
- NONE
- Motivation
- UNKNOWN
- Target sectors
- Technology, Enterprise, Financial Services, Healthcare, Manufacturing, Government
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 32
How n8n Multi-CVE Vulnerability Cascade works
n8n workflow automation platform critical multi-CVE vulnerability cascade — 10+ CVEs disclosed Dec 2025–Feb 2026 including expression sandbox escape to RCE (CVE-2025-68613, CVE-2026-25049), Pyodide Python sandbox escape (CVE-2025-68668, CVSS 9.9), arbitrary file write to RCE (CVE-2026-21877, CVSS 10.0), unauthenticated file access via webhook (CVE-2026-21858, CVSS 10.0), Merge node file write RCE (CVE-2026-25056), Git node command injection (CVE-2026-25053), and file access TOCTOU leading to full account takeover (CVE-2026-25052). Workflow automation platforms have code execution capabilities by design, making sandbox escapes catastrophic — authenticated users with workflow creation privileges achieve complete host server RCE.
n8n is a popular open-source workflow automation platform with 50,000+ GitHub stars and widespread enterprise deployment for business process automation, API integration, and AI agent orchestration. Between December 2025 and February 2026, n8n disclosed 10+ critical security vulnerabilities representing a systematic assault on the platform's security model. The primary vulnerability CVE-2025-68613 allows authenticated users with workflow creation privileges to escape the JavaScript expression sandbox through insufficient runtime isolation, achieving arbitrary code execution on the host server. CVE-2026-25049 represents additional expression escape exploits discovered after the initial fix. CVE-2025-68668 (CVSS 9.9) demonstrates that the Pyodide Python Code Node sandbox can also be escaped for RCE. Two CVEs scored CVSS 10.0: CVE-2026-21877 (arbitrary file write to RCE) and CVE-2026-21858 (unauthenticated file access via webhook). Additional critical vectors include CVE-2026-25056 (Merge node arbitrary file write to RCE), CVE-2026-25053 (Git node OS command injection), CVE-2026-25052 (file access TOCTOU race condition enabling arbitrary file read and full account takeover), and CVE-2026-25115 (additional Python sandbox escape). The breadth of vulnerabilities reveals a fundamental architectural challenge: workflow automation platforms grant users code execution capabilities by design through expression evaluation, code nodes, and system integrations — making every sandbox boundary a critical security surface. Public PoC exploits are available and active scanning has been observed targeting internet-exposed n8n instances.
MITRE ATT&CK techniques used in TL-2026-0094
collection
execution
T1053.003 Cron; T1059.004 Unix Shell; T1059.006 Python; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.002 Malicious File
privilege-escalation
T1068 Exploitation for Privilege Escalation; T1611 Escape to Host
command-and-control
discovery
T1082 System Information Discovery; T1083 File and Directory Discovery
persistence
T1098 Account Manipulation; T1505.003 Web Shell
initial-access
T1190 Exploit Public-Facing Application
lateral-movement
T1210 Exploitation of Remote Services
defense-evasion
T1211 Exploitation for Stealth
impact
T1486 Data Encrypted for Impact; T1496 Resource Hijacking
credential-access
T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555 Credentials from Password Stores
exfiltration
T1567 Exfiltration Over Web Service
resource-development
defense-impairment
Remediation for n8n Multi-CVE Vulnerability Cascade
Patches
- n8n 2.5.2 (latest stable addressing all CVEs)
- n8n 1.123.18 (LTS branch addressing all CVEs)
- n8n 2.4.8 (Python sandbox escape fix)
- n8n 2.0.0 (Pyodide sandbox escape fix)
Immediate actions
- Update n8n to version 2.5.2 or later immediately — this version addresses all disclosed CVEs
- Audit all n8n users with workflow creation privileges — each is a potential RCE vector
- Restrict n8n instance access to authenticated, trusted users only — never expose to internet without authentication
- Review all active workflows for suspicious expression patterns, Code node payloads, and Git node configurations
- Enable n8n audit logging to detect exploitation attempts
Workarounds
- Disable Code node and Python Code node for untrusted users
- Disable Git node integration if not required
- Restrict workflow creation to administrator-only
- Block outbound network from n8n container to limit post-exploitation
Longer-term hardening
- Deploy n8n in Docker containers with minimal host filesystem access and restricted network egress
- Implement least-privilege access control — separate workflow viewers from workflow creators
- Monitor n8n process for unexpected child processes, file system writes outside data directory, and outbound network connections
- Subscribe to n8n security advisories on GitHub for ongoing vulnerability disclosure
- Consider running n8n Code nodes in isolated execution environments (queue mode with separate workers)
- Implement WAF rules for webhook endpoints to prevent unauthenticated exploitation
CVEs associated with n8n Multi-CVE Vulnerability Cascade
CVE-2025-68613, CVE-2026-25049, CVE-2025-68668, CVE-2026-21877, CVE-2026-21858, CVE-2026-25056, CVE-2026-25053, CVE-2026-25052, CVE-2026-25115
Weaknesses (CWE) in n8n Multi-CVE Vulnerability Cascade
Timeline of n8n Multi-CVE Vulnerability Cascade
- Synacktiv publishes research on n8n multiple vulnerabilities (CVE-2023-27562, CVE-2023-27564) — SSRF and prototype pollution. Establishes n8n as a security research target. Source: https://www.synacktiv.com/sites/default/files/2023-05/Synacktiv-N8N-Multiple-Vulnerabilities_0.pdf
- CVE-2025-68668 disclosed — Pyodide Python Code Node sandbox escape to RCE (CVSS 9.9). CWE-693 Protection Mechanism Failure. Patched in n8n 2.0.0. Source: GitHub Security Advisory
- CVE-2026-21877 (CVSS 10.0, arbitrary file write to RCE) and CVE-2026-21858 (CVSS 10.0, unauthenticated file access via webhook) disclosed. Both represent critical pre-authentication attack vectors. Patched in 1.121.0/1.121.3. Source: GitHub Security Advisory
- Active scanning observed targeting internet-exposed n8n instances for newly disclosed vulnerabilities. Public PoC exploits available for expression sandbox escape. Source: GitHub Security Advisory
- n8n releases patches across multiple version branches: 2.5.2, 1.123.17, 1.123.18, 1.123.10. Addresses all disclosed expression escape, file write, command injection, and sandbox escape vulnerabilities. Source: https://github.com/n8n-io/n8n/releases
- Massive vulnerability disclosure wave: CVE-2025-68613 (expression injection RCE), CVE-2026-25049 (expression escape follow-up, CVSS 9.4), CVE-2026-25056 (Merge node file write RCE), CVE-2026-25053 (Git node command injection), CVE-2026-25052 (file access TOCTOU account takeover), CVE-2026-25115 (Python sandbox escape). Source: GitHub Security Advisories
- As of 2026-05-29, this n8n multi-CVE cascade remains actively exploited: CVE-2025-68613 was added to CISA KEV (Mar 11, due Mar 25) with confirmed Zerobot botnet exploitation since mid-Jan and a public Metasploit module. Patches exist, but Intel 471/Censys/Cyera report 26K-100K still-exposed instances and the CVSS-10.0 unauth "Ni8mare" (CVE-2026-21858) has live PoCs and active scanning.
Sources cited for n8n Multi-CVE Vulnerability Cascade
- GHSA-v98v-ff95-f3cp — n8n Expression Injection to RCE (CVE-2025-68613)
- GHSA-6cqr-8cfr-67f8 — n8n Expression Escape Follow-up (CVE-2026-25049)
- CVE-2025-68668 — Pyodide Sandbox Escape (CVSS 9.9)
- CVE-2026-21877 — Arbitrary File Write to RCE (CVSS 10.0)
- CVE-2026-21858 — Unauthenticated File Access (CVSS 10.0)
- CVE-2026-25056 — Merge Node File Write RCE (CVSS 9.4)
- CVE-2026-25053 — Git Node Command Injection (CVSS 9.4)
- CVE-2026-25052 — File Access TOCTOU Account Takeover (CVSS 9.4)
- CVE-2026-25115 — Python Sandbox Escape (CVSS 9.4)
- n8n GitHub Repository — Releases
- Synacktiv — n8n Multiple Vulnerabilities (2023 Historical)
- n8n Official Documentation — Isolation and Security
Detection coverage for TL-2026-0094
As of 2026-02-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0094 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.