#n8n

[ follow ]
fromTheregister
1 week ago

n8n's latest critical flaws bypass December fix

The vulnerabilities, collectively tracked as CVE-2026-25049, stem from weaknesses in how n8n sanitizes expressions inside workflows and could enable authenticated users to smuggle malicious code past safeguards introduced to fix CVE-2025-68613, a December 2025 vulnerability that already carried a near-perfect severity score. The new flaws carry a CVSS rating of 9.4, though some researchers argue the real-world impact could be even worse.
Information security
Information security
fromSecurityWeek
1 week ago

Critical N8n Sandbox Escape Could Lead to Server Compromise

A sandbox escape in n8n allowed arbitrary server command execution, exposing secrets and enabling full server compromise; fixed in n8n 2.4.0.
Information security
fromThe Hacker News
1 week ago

Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows

A critical n8n vulnerability (CVE-2026-25049) allows authenticated workflow creators to execute arbitrary system commands, risking full server compromise.
fromBleepingComputer
1 week ago

Critical n8n flaws disclosed along with public exploits

Multiple critical vulnerabilities in the popular n8n open-source workflow automation platform allow escaping the confines of the environment and taking complete control of the host server. Collectively tracked as CVE-2026-25049, the issues can be exploited by any authenticated user who can create or edit workflows on the platform to perform unrestricted remote code execution on the n8n server. Researchers at several cybersecurity companies reported the problems, which stem from n8n's sanitization mechanism and bypass the patch for CVE-2025-68613, another critical flaw addressed on December 20.
Information security
#remote-code-execution
Information security
fromThe Hacker News
1 month ago

n8n Supply Chain Attack Abuses Community Nodes to Steal OAuth Tokens

Malicious npm packages posing as n8n integrations stole OAuth tokens by prompting account links and exfiltrating credentials to attacker-controlled servers.
#cve-2026-21858
Information security
fromThe Hacker News
1 month ago

Weekly Recap: AI Automation Exploits, Telecom Espionage, Prompt Poaching & More

Small security oversights in widely used tools enable attackers to execute remote code and scale compromises rapidly, exemplified by n8n CVE‑2026‑21858.
fromTechzine Global
1 month ago

'Ni8mare' vulnerability affects n8n platform with a score of 10.0

The vulnerability arises from a so-called "Content-Type Confusion" in n8n's webhook processing. Webhooks are the starting point for workflows and capture incoming data from forms, chat messages, and WhatsApp notifications. By manipulating the Content-Type header, an attacker can overwrite the req.body.files variable and thus read arbitrary files from the system. The researchers demonstrated how the vulnerability can escalate to Remote Code Execution.
Information security
Information security
fromThe Hacker News
1 month ago

New n8n Vulnerability (9.9 CVSS) Lets Authenticated Users Execute System Commands

Authenticated users with workflow create/modify permissions can execute arbitrary operating system commands on hosts running vulnerable n8n versions prior to 2.0.0.
Information security
fromThe Hacker News
1 month ago

Critical n8n Flaw (CVSS 9.9) Enables Arbitrary Code Execution Across Thousands of Instances

Critical RCE vulnerability CVE-2025-68613 in n8n can allow authenticated users to execute arbitrary code; apply patches immediately or restrict workflow editing.
fromLogRocket Blog
3 months ago

I tried OpenAI's AgentKit: Does it make Zapier and n8n obsolete? - LogRocket Blog

For years, automation has promised to make our lives easier - and to some extent, it has. But in 2025, things feel different. Traditional automation resembles a giant "if-else" statement that struggles to adapt to diverse situations. Agentic AI changes that narrative by enabling workflows to adjust and optimize themselves for countless scenarios that were difficult for older automation tools. In October 2025, OpenAI launched its AgentKit tool for building AI agents, and let me tell you, it is glorious!
Artificial intelligence
#automation
Marketing tech
fromGeeky Gadgets
3 months ago

Turn a Single Photo Into a Stunning Video Advert in Seconds Using AI

AI and no-code platforms convert a single static image into a professional 30-second commercial without production teams or extensive editing.
#workflow-automation
[ Load more ]