Python Code Execution Vulnerability in n8n Workflow Automation Platform
CVE-2026-25115

9.4CRITICAL

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
4 February 2026

What is CVE-2026-25115?

n8n is an open-source workflow automation platform that experienced a vulnerability in its Python Code node feature. Prior to version 2.4.8, this vulnerability permitted authenticated users to escape the Python sandbox environment, thus enabling them to execute arbitrary code outside the restricted security context. This issue poses significant risks to the integrity and confidentiality of the workflows running on the platform. The vulnerability has been successfully mitigated in version 2.4.8, emphasizing the importance of keeping software updated to protect against potential threats.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

n8n < 2.4.8

References

CVSS V4

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.