n8n
cpe:2.3:a:n8n:n8n:*:*:*:*:node.js:*:*
- < 1.123.32
- < 2.17.4
- < 2.18.1
A vulnerability allowing authenticated users to escape the sandbox of the Python Code Node in n8n workflows has been identified. This issue, present in versions prior to 1.123.32, 2.17.4, and 2.18.1, allows for arbitrary code execution on the task runner container. The vulnerability only affects instances with the Python Task Runner enabled.
Exploitation of this vulnerability could lead to unauthorized arbitrary code execution on the task runner container.
Users should upgrade to n8n versions 1.123.32, 2.17.4, or 2.18.1. If an immediate upgrade is not possible, consider limiting workflow permissions to trusted users and disabling the Python Code Node or the Python Task Runner entirely.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.