Sandbox escape in n8n leads to code execution on the host

JFrog Security Research has disclosed two vulnerabilities in the open-source automation platform n8n that let an attacker escape the built-in sandbox and execute code on the host. CVE-2026-1470 is a critical flaw in n8n's JavaScript expression evaluation engine, rated CVSS 9.9. CVE-2026-0863 is rated CVSS 8.5 and sits in the Python Code node's task executor. Both stem from gaps in the platform's sanitisation logic, meaning anyone able to create or modify a workflow can run arbitrary commands on the machine hosting n8n. Users are advised to upgrade to the versions the researchers recommend.

What this means for your organisation

n8n often sits at the centre of the integration landscape, holding API keys and access to line-of-business systems, email and cloud services. These flaws change what a workflow editor is: no longer a low-risk business-side tool, but a route to code execution inside your infrastructure. If you granted broad editing rights to speed up automation, that decision is what now needs revisiting.

Berigo recommends

  • Upgrade n8n to the patched version, prioritising instances accessible to many users.
  • Review who is entitled to create and modify workflows, and reduce it to those who genuinely need it.
  • Run n8n with least privilege and in a segmented network, not alongside core systems.
  • Rotate API keys and secrets stored in n8n if the instance has been broadly accessible.

Source

Related services

Security that is understood, governed and works.

Let us help you turn security into an advantage, not a cost. Get in touch for a no-obligation conversation about where your organisation stands and what to prioritise first.

Get in touch