BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

New Critical n8n Flaw Allows Remote Code Execution

Critical n8n flaw enables remote command execution via webhooks, bypassing December 2025 patch; update immediately.

  • A critical flaw (CVE-2026-25049) in the automation platform n8n enables authenticated users to execute system commands, representing a bypass for a patch issued in December 2025.
  • An attacker can create a public webhook in a workflow to remotely trigger the exploit, potentially compromising the server and stealing sensitive credentials and data.
  • The vulnerability stems from a mismatch between TypeScript’s compile-time type checks and JavaScript’s runtime behavior, allowing malicious values to bypass sanitization.
  • Versions before 1.123.17 and 2.5.2 are affected, and users are urged to patch immediately or restrict workflow permissions and deploy in a hardened environment.

On February 5, 2026, security researchers disclosed a severe vulnerability in the popular n8n workflow automation platform that allows authenticated attackers to run arbitrary commands on the host system. This latest flaw, tracked as CVE-2026-25049 with a CVSS score of 9.4, is a direct bypass for safeguards implemented to fix an earlier critical issue, CVE-2025-68613.

- Advertisement -

According to the advisory released by n8n’s maintainers, the weakness lies in inadequate expression sanitization. Consequently, a user with permissions to create workflows could craft malicious expressions to trigger unintended command execution.

The vulnerability was identified by a group of ten researchers, including Fatih Çelik. In a technical analysis, Çelik explained that the new flaw is essentially the same vulnerability, as it escapes the n8n expression sandbox.

SecureLayer7 noted that pairing the bug with a public webhook makes it remotely exploitable. An attacker can therefore create a workflow, add a JavaScript payload, and wait for anyone online to trigger it.

Successful exploitation grants significant control. “The attack requires nothing special. If you can create a workflow, you can own the server,” said Pillar Security‘s Eilon Cohen, whose report detailed risks like stealing API keys and hijacking AI workflows.

- Advertisement -

Endor Labs’ Cris Staicu explained the root cause is a mismatch between TypeScript’s compile-time types and JavaScript’s runtime. Attackers can thus pass non-string values that bypass checks entirely.

The affected versions are below 1.123.17 and 2.5.2. Meanwhile, if patching is delayed, n8n recommends restricting workflow permissions and deploying in a hardened, restricted environment as a workaround.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Saylor’s Bitcoin Strategy Defies Bear Flag Threat

Bitcoin is trading in a bear flag pattern that suggests a potential 30% drop...

Salary Required for a $1M Home Loan Nears $200,000

Securing a mortgage for a $1 million home typically requires a minimum annual salary...

Arc Blockchain to Launch With Quantum-Resistant Tech

Arc Network will launch its mainnet with built-in support for post-quantum signatures, backed by...

RateON Review: A Convenient Crypto Exchange Platform With Broad Coverage and Extra Rewards

TABLE OF CONTENTSWhat Is RateON?Supported Coins and NetworksHow the Exchange Process WorksRates and Overall...

BlackRock-Backed Broadridge Scales $8T Tokenization

Broadridge is scaling its blockchain infrastructure, which already handles $8 trillion in tokenized assets...

Must Read

What Are Sniper Bots Used in Defi Trading?

You've heard about DeFi, but what about sniper bots? These high-speed trading tools are shaking up the crypto scene.But don't fret, you're not...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading