#VU124007 Protection Mechanism Failure in n8n - CVE-2026-27495

 

#VU124007 Protection Mechanism Failure in n8n - CVE-2026-27495

Published: March 13, 2026


Vulnerability identifier: #VU124007
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2026-27495
CWE-ID: CWE-693
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
n8n
Software vendor:
n8n

Description

The vulnerability allows a remote user to bypass implemented security restrictions.

The vulnerability exists due to insufficient implementation of security measures. A remote user with permission to create or modify workflows can bypass the JavaScript Task Runner sandbox and execute arbitrary code outside the sandbox boundary.


Remediation

Install updates from vendor's website.

External links