BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Critical n8n Flaw Allows Remote Code Execution

Critical n8n flaw enables remote command execution via webhooks, bypassing December 2025 patch; update immediately.

  • A critical flaw (CVE-2026-25049) in the automation platform n8n enables authenticated users to execute system commands, representing a bypass for a patch issued in December 2025.
  • An attacker can create a public webhook in a workflow to remotely trigger the exploit, potentially compromising the server and stealing sensitive credentials and data.
  • The vulnerability stems from a mismatch between TypeScript’s compile-time type checks and JavaScript’s runtime behavior, allowing malicious values to bypass sanitization.
  • Versions before 1.123.17 and 2.5.2 are affected, and users are urged to patch immediately or restrict workflow permissions and deploy in a hardened environment.

On February 5, 2026, security researchers disclosed a severe vulnerability in the popular n8n workflow automation platform that allows authenticated attackers to run arbitrary commands on the host system. This latest flaw, tracked as CVE-2026-25049 with a CVSS score of 9.4, is a direct bypass for safeguards implemented to fix an earlier critical issue, CVE-2025-68613.

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading

According to the advisory released by n8n’s maintainers, the weakness lies in inadequate expression sanitization. Consequently, a user with permissions to create workflows could craft malicious expressions to trigger unintended command execution.

The vulnerability was identified by a group of ten researchers, including Fatih Çelik. In a technical analysis, Çelik explained that the new flaw is essentially the same vulnerability, as it escapes the n8n expression sandbox.

SecureLayer7 noted that pairing the bug with a public webhook makes it remotely exploitable. An attacker can therefore create a workflow, add a JavaScript payload, and wait for anyone online to trigger it.

Successful exploitation grants significant control. “The attack requires nothing special. If you can create a workflow, you can own the server,” said Pillar Security‘s Eilon Cohen, whose report detailed risks like stealing API keys and hijacking AI workflows.

- Advertisement -

Endor Labs’ Cris Staicu explained the root cause is a mismatch between TypeScript’s compile-time types and JavaScript’s runtime. Attackers can thus pass non-string values that bypass checks entirely.

The affected versions are below 1.123.17 and 2.5.2. Meanwhile, if patching is delayed, n8n recommends restricting workflow permissions and deploying in a hardened, restricted environment as a workaround.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

XRP Hits $1.50, Eyes $1.60 Break Amid Record Holders

XRP (XRP) traded at $1.50 on Tuesday, a 3% rise in the past 24...

Study: Corporate AI Security Lags Due to Skills Gap

Two-thirds of security leaders lack visibility into how AI is used within their organizations,...

Google AI Predicts GOOGL at $328.50 by 2026

Alphabet stock (GOOGL) is consolidating near $300, supported by recent acquisition news.Gemini AI predicts...

Mastercard Acquires Stablecoin Firm BVNK for $1.8B

Mastercard confirms its agreement to acquire stablecoin firm BVNK for a potential total of...

Bitcoin Drops $2K After Near $76K High as Alts Rise

Bitcoin retreated from a near $76,000 high, triggering over $490 million in leveraged position...

Must Read

Top 10 BEST Crypto Trading Books for New Traders

If you're thinking of diving into the crypto trading space, acquiring solid knowledge isn't just recommended - it's essential to protect your investment.Learning...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading