# n8n Multi-CVE Vulnerability Cascade — Expression Sandbox Escape, Pyodide RCE, Arbitrary File Write, Command Injection (9 CVEs, 2× CVSS 10.0)

> n8n workflow automation platform critical multi-CVE vulnerability cascade — 10+ CVEs disclosed Dec 2025–Feb 2026 including expression sandbox escape to RCE (CVE-2025-68613, CVE-2026-25049), Pyodide Python sandbox escape (CVE-2025-68668, CVSS 9.9), arbitrary file write to RCE (CVE-2026-21877, CVSS 10.0), unauthenticated file access via webhook (CVE-2026-21858, CVSS 10.0), Merge node file write RCE (CVE-2026-25056), Git node command injection (CVE-2026-25053), and file access TOCTOU leading to full account takeover (CVE-2026-25052). Workflow automation platforms have code execution capabilities by design, making sandbox escapes catastrophic — authenticated users with workflow creation privileges achieve complete host server RCE.

- **Published:** 2026-02-04T22:15:00Z
- **Last reviewed:** 2026-02-04T22:15:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-0094
- **ID:** TL-2026-0094
- **Severity:** CRITICAL
- **Category:** VULNERABILITY
- **Status:** ACTIVE
- **Detections:** 9 · **IOCs:** 32 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2025-68613, CVE-2026-25049, CVE-2025-68668, CVE-2026-21877, CVE-2026-21858, CVE-2026-25056, CVE-2026-25053, CVE-2026-25052, CVE-2026-25115

## Description

n8n is a popular open-source workflow automation platform with 50,000+ GitHub stars and widespread enterprise deployment for business process automation, API integration, and AI agent orchestration. Between December 2025 and February 2026, n8n disclosed 10+ critical security vulnerabilities representing a systematic assault on the platform's security model. The primary vulnerability CVE-2025-68613 allows authenticated users with workflow creation privileges to escape the JavaScript expression sandbox through insufficient runtime isolation, achieving arbitrary code execution on the host server. CVE-2026-25049 represents additional expression escape exploits discovered after the initial fix. CVE-2025-68668 (CVSS 9.9) demonstrates that the Pyodide Python Code Node sandbox can also be escaped for RCE. Two CVEs scored CVSS 10.0: CVE-2026-21877 (arbitrary file write to RCE) and CVE-2026-21858 (unauthenticated file access via webhook). Additional critical vectors include CVE-2026-25056 (Merge node arbitrary file write to RCE), CVE-2026-25053 (Git node OS command injection), CVE-2026-25052 (file access TOCTOU race condition enabling arbitrary file read and full account takeover), and CVE-2026-25115 (additional Python sandbox escape). The breadth of vulnerabilities reveals a fundamental architectural challenge: workflow automation platforms grant users code execution capabilities by design through expression evaluation, code nodes, and system integrations — making every sandbox boundary a critical security surface. Public PoC exploits are available and active scanning has been observed targeting internet-exposed n8n instances.

## MITRE ATT&CK

- T1059.007 JavaScript
- T1059.006 Python
- T1059.004 Unix Shell
- T1203 Exploitation for Client Execution
- T1068 Exploitation for Privilege Escalation
- T1611 Escape to Host
- T1211 Exploitation for Stealth
- T1552.001 Credentials In Files
- T1528 Steal Application Access Token
- T1083 File and Directory Discovery
- T1082 System Information Discovery
- T1210 Exploitation of Remote Services
- T1005 Data from Local System
- T1505.003 Web Shell
- T1053.003 Cron
- T1190 Exploit Public-Facing Application
- T1486 Data Encrypted for Impact
- T1583 Acquire Infrastructure
- T1071.001 Web Protocols
- T1204.002 Malicious File
- T1098 Account Manipulation
- T1685 Disable or Modify Tools
- T1496 Resource Hijacking
- T1567 Exfiltration Over Web Service
- T1555 Credentials from Password Stores

## Sources

- [GHSA-v98v-ff95-f3cp — n8n Expression Injection to RCE (CVE-2025-68613)](https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp)
- [GHSA-6cqr-8cfr-67f8 — n8n Expression Escape Follow-up (CVE-2026-25049)](https://github.com/n8n-io/n8n/security/advisories/GHSA-6cqr-8cfr-67f8)
- [CVE-2025-68668 — Pyodide Sandbox Escape (CVSS 9.9)](https://github.com/n8n-io/n8n/security/advisories)
- [n8n GitHub Repository — Releases](https://github.com/n8n-io/n8n/releases)
- [Synacktiv — n8n Multiple Vulnerabilities (2023 Historical)](https://www.synacktiv.com/sites/default/files/2023-05/Synacktiv-N8N-Multiple-Vulnerabilities_0.pdf)
- [n8n Official Documentation — Isolation and Security](https://docs.n8n.io/hosting/configuration/configuration-examples/isolation/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-0094
