Executive brief
n8n is a workflow automation platform that allows users to create and execute complex tasks via a JavaScript engine. An authenticated user with workflow creation permissions can break out of the JavaScript sandbox to execute arbitrary code on the host system (if using the default internal runner mode) or on shared task runner infrastructure, potentially compromising the entire n8n instance and any systems it has access to.
Technical details
The vulnerability is a sandbox escape in n8n's JavaScript Task Runner component (CWE-94: Improper Control of Generation of Code). An authenticated user with permission to create or modify workflows can exploit improper sandbox isolation to execute arbitrary code outside the intended sandbox boundary. The attack requires only network access and valid authentication credentials; no special privileges or user interaction are needed. When using the default internal Task Runner mode (N8N_RUNNERS_ENABLED=true), exploitation results in full code execution on the n8n host system. When using external Task Runners, the attacker gains execution context on the shared runner infrastructure. Patches have been released in versions 1.123.22, 2.9.3, and 2.10.1.
Affected products
- n8n n8n versions before 1.123.22, 2.0.0 to 2.9.2, and 2.10.0
Timeline
- 2026-02-25: disclosed: Advisory published
- 2026-02-25: patched: Patches available in versions 1.123.22, 2.9.3, and 2.10.1