Threat reportVulnerabilityTL-2026-0094

n8n Multi-CVE Vulnerability Cascade — Expression Sandbox Escape, Pyodide RCE, Arbitrary File Write, Command Injection (9 CVEs, 2× CVSS 10.0)

criticalACTIVE

n8n Multi-CVE Vulnerability Cascade (TL-2026-0094) is a critical-severity software vulnerability, first published 2026-02-04. It has no confirmed attribution, references 9 CVEs (CVE-2025-68613, CVE-2026-25049, CVE-2025-68668), maps to 25 MITRE ATT&CK techniques (T1005, T1053.003, T1059.004), and is covered by 9 detection rules and 32 indicators of compromise.

Severity
CRITICALAssessed severity
CVEs
9Referenced vulnerabilities
Techniques
25MITRE ATT&CK
Actors
0Not attributed
Detection rules
9SPL · KQL · Sigma
IOCs
32Indicators of compromise

Key facts for TL-2026-0094

Threat ID
TL-2026-0094
Severity
CRITICAL
Status
ACTIVE
Category
VULNERABILITY
First published
Last reviewed
Attribution confidence
NONE
Motivation
UNKNOWN
Target sectors
Technology, Enterprise, Financial Services, Healthcare, Manufacturing, Government
Target regions
Global
Detection rules
9
Indicators of compromise
32

How n8n Multi-CVE Vulnerability Cascade works

n8n workflow automation platform critical multi-CVE vulnerability cascade — 10+ CVEs disclosed Dec 2025–Feb 2026 including expression sandbox escape to RCE (CVE-2025-68613, CVE-2026-25049), Pyodide Python sandbox escape (CVE-2025-68668, CVSS 9.9), arbitrary file write to RCE (CVE-2026-21877, CVSS 10.0), unauthenticated file access via webhook (CVE-2026-21858, CVSS 10.0), Merge node file write RCE (CVE-2026-25056), Git node command injection (CVE-2026-25053), and file access TOCTOU leading to full account takeover (CVE-2026-25052). Workflow automation platforms have code execution capabilities by design, making sandbox escapes catastrophic — authenticated users with workflow creation privileges achieve complete host server RCE.

n8n is a popular open-source workflow automation platform with 50,000+ GitHub stars and widespread enterprise deployment for business process automation, API integration, and AI agent orchestration. Between December 2025 and February 2026, n8n disclosed 10+ critical security vulnerabilities representing a systematic assault on the platform's security model. The primary vulnerability CVE-2025-68613 allows authenticated users with workflow creation privileges to escape the JavaScript expression sandbox through insufficient runtime isolation, achieving arbitrary code execution on the host server. CVE-2026-25049 represents additional expression escape exploits discovered after the initial fix. CVE-2025-68668 (CVSS 9.9) demonstrates that the Pyodide Python Code Node sandbox can also be escaped for RCE. Two CVEs scored CVSS 10.0: CVE-2026-21877 (arbitrary file write to RCE) and CVE-2026-21858 (unauthenticated file access via webhook). Additional critical vectors include CVE-2026-25056 (Merge node arbitrary file write to RCE), CVE-2026-25053 (Git node OS command injection), CVE-2026-25052 (file access TOCTOU race condition enabling arbitrary file read and full account takeover), and CVE-2026-25115 (additional Python sandbox escape). The breadth of vulnerabilities reveals a fundamental architectural challenge: workflow automation platforms grant users code execution capabilities by design through expression evaluation, code nodes, and system integrations — making every sandbox boundary a critical security surface. Public PoC exploits are available and active scanning has been observed targeting internet-exposed n8n instances.

MITRE ATT&CK techniques used in TL-2026-0094

collection

T1005 Data from Local System

execution

T1053.003 Cron; T1059.004 Unix Shell; T1059.006 Python; T1059.007 JavaScript; T1203 Exploitation for Client Execution; T1204.002 Malicious File

privilege-escalation

T1068 Exploitation for Privilege Escalation; T1611 Escape to Host

command-and-control

T1071.001 Web Protocols

discovery

T1082 System Information Discovery; T1083 File and Directory Discovery

persistence

T1098 Account Manipulation; T1505.003 Web Shell

initial-access

T1190 Exploit Public-Facing Application

lateral-movement

T1210 Exploitation of Remote Services

defense-evasion

T1211 Exploitation for Stealth

impact

T1486 Data Encrypted for Impact; T1496 Resource Hijacking

credential-access

T1528 Steal Application Access Token; T1552.001 Credentials In Files; T1555 Credentials from Password Stores

exfiltration

T1567 Exfiltration Over Web Service

resource-development

T1583 Acquire Infrastructure

defense-impairment

T1685 Disable or Modify Tools

Remediation for n8n Multi-CVE Vulnerability Cascade

Patches

  • n8n 2.5.2 (latest stable addressing all CVEs)
  • n8n 1.123.18 (LTS branch addressing all CVEs)
  • n8n 2.4.8 (Python sandbox escape fix)
  • n8n 2.0.0 (Pyodide sandbox escape fix)

Immediate actions

  • Update n8n to version 2.5.2 or later immediately — this version addresses all disclosed CVEs
  • Audit all n8n users with workflow creation privileges — each is a potential RCE vector
  • Restrict n8n instance access to authenticated, trusted users only — never expose to internet without authentication
  • Review all active workflows for suspicious expression patterns, Code node payloads, and Git node configurations
  • Enable n8n audit logging to detect exploitation attempts

Workarounds

  • Disable Code node and Python Code node for untrusted users
  • Disable Git node integration if not required
  • Restrict workflow creation to administrator-only
  • Block outbound network from n8n container to limit post-exploitation

Longer-term hardening

  • Deploy n8n in Docker containers with minimal host filesystem access and restricted network egress
  • Implement least-privilege access control — separate workflow viewers from workflow creators
  • Monitor n8n process for unexpected child processes, file system writes outside data directory, and outbound network connections
  • Subscribe to n8n security advisories on GitHub for ongoing vulnerability disclosure
  • Consider running n8n Code nodes in isolated execution environments (queue mode with separate workers)
  • Implement WAF rules for webhook endpoints to prevent unauthenticated exploitation

CVEs associated with n8n Multi-CVE Vulnerability Cascade

CVE-2025-68613, CVE-2026-25049, CVE-2025-68668, CVE-2026-21877, CVE-2026-21858, CVE-2026-25056, CVE-2026-25053, CVE-2026-25052, CVE-2026-25115

Weaknesses (CWE) in n8n Multi-CVE Vulnerability Cascade

CWE-913, CWE-693, CWE-434, CWE-20, CWE-78, CWE-367

Timeline of n8n Multi-CVE Vulnerability Cascade

  • Synacktiv publishes research on n8n multiple vulnerabilities (CVE-2023-27562, CVE-2023-27564) — SSRF and prototype pollution. Establishes n8n as a security research target. Source: https://www.synacktiv.com/sites/default/files/2023-05/Synacktiv-N8N-Multiple-Vulnerabilities_0.pdf
  • CVE-2025-68668 disclosed — Pyodide Python Code Node sandbox escape to RCE (CVSS 9.9). CWE-693 Protection Mechanism Failure. Patched in n8n 2.0.0. Source: GitHub Security Advisory
  • CVE-2026-21877 (CVSS 10.0, arbitrary file write to RCE) and CVE-2026-21858 (CVSS 10.0, unauthenticated file access via webhook) disclosed. Both represent critical pre-authentication attack vectors. Patched in 1.121.0/1.121.3. Source: GitHub Security Advisory
  • Active scanning observed targeting internet-exposed n8n instances for newly disclosed vulnerabilities. Public PoC exploits available for expression sandbox escape. Source: GitHub Security Advisory
  • n8n releases patches across multiple version branches: 2.5.2, 1.123.17, 1.123.18, 1.123.10. Addresses all disclosed expression escape, file write, command injection, and sandbox escape vulnerabilities. Source: https://github.com/n8n-io/n8n/releases
  • Massive vulnerability disclosure wave: CVE-2025-68613 (expression injection RCE), CVE-2026-25049 (expression escape follow-up, CVSS 9.4), CVE-2026-25056 (Merge node file write RCE), CVE-2026-25053 (Git node command injection), CVE-2026-25052 (file access TOCTOU account takeover), CVE-2026-25115 (Python sandbox escape). Source: GitHub Security Advisories
  • As of 2026-05-29, this n8n multi-CVE cascade remains actively exploited: CVE-2025-68613 was added to CISA KEV (Mar 11, due Mar 25) with confirmed Zerobot botnet exploitation since mid-Jan and a public Metasploit module. Patches exist, but Intel 471/Censys/Cyera report 26K-100K still-exposed instances and the CVSS-10.0 unauth "Ni8mare" (CVE-2026-21858) has live PoCs and active scanning.

Sources cited for n8n Multi-CVE Vulnerability Cascade

Detection coverage for TL-2026-0094

As of 2026-02-04, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-0094 across Splunk SPL, Microsoft KQL and Sigma, covering 32 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.

9 detection rules (Splunk SPL, Microsoft KQL, Sigma) · Blue and above. Compare plans
32 indicators of compromise · Red and above. Compare plans

Threadlinqs Intelligence — Real-Time Threat Detection Platform

[ 0 threats ] [ 0 det ] [ CRIT: 0 ] [ HIGH: 0 ]
// threat_feed
$ sort --newest
Showing all threats

Live intelligence console

Threat level
Fig. 01 · Threat weatherIndexing the archive…
1 square = 1 threat · click to open

Latest Threats