← voltar
CVE-2026-49444

n8n: Python sandbox escape

CVSS 7.1 HIGHEPSS 0.4%CWE-20
n8n is an open source workflow automation platform. Prior to 1.123.48, 2.21.8, and 2.22.4, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This vulnerability is fixed in 1.123.48, 2.21.8, and 2.22.4.
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N
Produtos afetados
n8n-io · n8n

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →