n8n Flaws Expose Automation Tool Risks, Threaten AI Agent Security
n8n is an open-source workflow automation platform that connects services including Gmail, Slack, Notion and ChatGPT, and has more than 230,000 active users worldwide. Because its workflows often hold API keys, OAuth permissions and cloud credentials, it has evolved from a time-saving tool into a gateway to enterprise systems. As AI agents gain the ability to generate and execute commands autonomously, model errors, account theft or internal abuse could escalate into cross-system risks.
Cybersecurity firm Pillar Security disclosed CVE-2026-27577 and CVE-2026-27493, with CVSS scores of 9.4 and 9.5, respectively. The first allows authenticated users to escape the sandbox by exploiting a gap in AST rewriting, while the second enables zero-click execution of shell commands through public forms. n8n released patched versions 2.10.1, 2.9.3 and 1.123.22 on February 25, 2026. n8n Cloud is already protected, but self-hosted users must upgrade.
All Coverage
2 original reportsThe Backstory
The history behind this eventNo historical echoes for this signal
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.