Signal
Critical n8n CVE-2026-25049 sandbox escape could enable server command execution
Evidence first: scan the strongest sources, then decide whether to go deeper.
Published 2026-02-05 06:16 UTCUpdated 2026-02-05 11:38 UTC
rss
cvevulnerabilitysandbox_escaperceworkflow_automationpatch_bypass
Source links open
Source links and full evidence are open here. Archive history, compare-over-time, alerts, exports, API, integrations, and workflow are paid.
No card needed for the free brief.
Evidence trail (top sources)
top sources (3 domains)domains are deduped. counts indicate coverage, not truth.3 top sources shown
Overview
Security outlets report a newly disclosed critical vulnerability in the n8n workflow automation platform that can be triggered via malicious workflows to escape the sandbox and execute arbitrary system commands. Coverage emphasizes that the weakness stems from inadequate sanitization of JavaScript expressions and is described as bypassing safeguards introduced for a prior critical n8n issue.
Entities
n8nPillar Security
Score total
1.3
Momentum 24h
3
Posts
3
Origins
3
Source types
1
Duplicate ratio
0%
Why now
- New disclosure of CVE-2026-25049 reported across multiple security outlets
- Details highlight sandbox sanitization weaknesses in JavaScript expression handling
- Coverage links it to safeguards added for an earlier critical n8n CVE
Why it matters
- Critical severity: reported to enable arbitrary system command execution
- Workflow access risk: malicious workflows could be a practical attack path
- Patch-bypass framing raises concern about effectiveness of prior safeguards
LLM analysis
Topic mix: lowPromo risk: lowSource quality: high
Recurring claims
- CVE-2026-25049 is a critical n8n vulnerability (CVSS 9.4) that could enable arbitrary system command execution.
- The issue is tied to sandbox sanitization of JavaScript expressions and is characterized as a sandbox escape.
- Reporting frames the flaw as bypassing safeguards/patches introduced for an earlier critical n8n vulnerability (CVE-2025-68613).
How sources frame it
- The Hacker News: neutral
- SecurityWeek: neutral
- The Register: neutral
Reports converge on a critical n8n sandbox escape (CVE-2026-25049) enabling server-side command execution via malicious workflows.
All evidence
All evidence
n8n security woes roll on as new critical flaws bypass December fix
The Register Security · go.theregister.com · 2026-02-05 11:38 UTC
Critical N8n Sandbox Escape Could Lead to Server Compromise
SecurityWeek · securityweek.com · 2026-02-05 11:23 UTC
Critical n8n Flaw CVE-2026-25049 Enables System Command Execution via Malicious Workflows
thehackernews · thehackernews.com · 2026-02-05 06:16 UTC
Show filters & breakdown
Posts loaded: 0Publishers: 3Origin domains: 3Duplicates: -
Showing 3 / 0
Top publishers (this list)
- The Register Security (1)
- SecurityWeek (1)
- thehackernews (1)
Top origin domains (this list)
- go.theregister.com (1)
- securityweek.com (1)
- thehackernews.com (1)