Expression Injection Vulnerability in n8n Open Source Workflow Automation Platform
CVE-2026-27493
What is CVE-2026-27493?
The n8n platform contains a second-order expression injection vulnerability within its Form nodes. This issue allows an unauthenticated attacker to submit specially crafted form data that can inject and evaluate arbitrary n8n expressions. If combined with a sandbox escape, it could lead to remote code execution on the host system. The vulnerability arises when a form node's field value, prefixed with an = character, is treated as an expression, resulting in a double-evaluation of the data. Although the conditions required for exploitation are quite specific, this vulnerability underscores the need for careful handling of user input in workflow design. Administrators are advised to upgrade to patched versions or implement temporary mitigations while maintaining awareness of the risks involved.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
n8n < 1.123.22 < 1.123.22
n8n >= 2.0.0, < 2.9.3 < 2.0.0, 2.9.3
n8n >= 2.10.0, < 2.10.1 < 2.10.0, 2.10.1
References
CVSS V4
Timeline
Vulnerability published
Vulnerability Reserved
