Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

Multiple vulnerabilities in n8n workflow automation platform

Six vulnerabilities were disclosed in n8n affecting versions before 2.35.4 and 2.36.x before 2.36.2, including credential exfiltration, sandbox escapes, query injection, and remote code execution in multiple nodes.

Disclosed 3 September 2026 · Record updated 13 September 2026

Impact

Attackers with various privilege levels could execute arbitrary code, exfiltrate credentials, bypass sandbox restrictions, perform query injection attacks, or exploit git operations to achieve remote code execution on the n8n process.

Our coverage

No articles linked to this incident yet.

Sources

  1. github.comhttps://github.com/advisories/GHSA-4qfv-x7mh-xjhv
  2. github.comhttps://github.com/advisories/GHSA-qhgm-jv25-h5h2
  3. github.comhttps://github.com/advisories/GHSA-733v-xpr6-gwgq
  4. github.comhttps://github.com/advisories/GHSA-7mp8-q29w-rc68
  5. github.comhttps://github.com/advisories/GHSA-8jv2-7jr5-2p67
  6. github.comhttps://github.com/advisories/GHSA-jjvm-mg9c-jcjc