Arbitrary Code Execution Vulnerability in n8n Workflow Automation Platform
CVE-2026-49444
7.1HIGH
What is CVE-2026-49444?
An authenticated user in n8n prior to specified versions could leverage the ability to create or modify workflows with a Python Code Node, inadvertently escaping the sandbox environment. This flaw enables the execution of arbitrary code in the task runner container, potentially compromising the system. Users are urged to update to the latest versions to mitigate this risk and ensure the integrity of their workflows.
Affected Version(s)
n8n < 1.123.48 < 1.123.48
n8n >= 2.0.0-rc.0, < 2.21.8 < 2.0.0-rc.0, 2.21.8
n8n >= 2.22.0, < 2.22.4 < 2.22.0, 2.22.4
