Arbitrary Code Execution Vulnerability in n8n Workflow Automation Platform
CVE-2026-42234

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
4 May 2026

What is CVE-2026-42234?

An authentication flaw in n8n, an open-source workflow automation platform, affects users with permissions to create or modify workflows that utilize a Python Code Node. Prior to versions 1.123.32, 2.17.4, and 2.18.1, such authenticated users could escape the designated sandbox environment, potentially leading to arbitrary code execution within the task runner container. This vulnerability is restricted to instances where the Python Task Runner is enabled, and has been satisfactorily patched in the aforementioned versions, ensuring enhanced security for n8n users.

Affected Version(s)

n8n < 1.123.32 < 1.123.32

n8n >= 2.17.0, < 2.17.4 < 2.17.0, 2.17.4

n8n >= 2.18.0, < 2.18.1 < 2.18.0, 2.18.1

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.