Mark RadarMARK RADAR
EN

n8n Flaws Expose Automation Tool Risks, Threaten AI Agent Security

2 reports · First detected 2026-03-09 · Last active 2026-03-17

n8n is an open-source workflow automation platform that connects services including Gmail, Slack, Notion and ChatGPT, and has more than 230,000 active users worldwide. Because its workflows often hold API keys, OAuth permissions and cloud credentials, it has evolved from a time-saving tool into a gateway to enterprise systems. As AI agents gain the ability to generate and execute commands autonomously, model errors, account theft or internal abuse could escalate into cross-system risks.

Cybersecurity firm Pillar Security disclosed CVE-2026-27577 and CVE-2026-27493, with CVSS scores of 9.4 and 9.5, respectively. The first allows authenticated users to escape the sandbox by exploiting a gap in AST rewriting, while the second enables zero-click execution of shell commands through public forms. n8n released patched versions 2.10.1, 2.9.3 and 1.123.22 on February 25, 2026. n8n Cloud is already protected, but self-hosted users must upgrade.

All Coverage

2 original reports

The Backstory

The history behind this event

No historical echoes for this signal

Mark Radar|MARK RADAR