n8n is an open source workflow automation platform. Prior to version 2.4.8, a vulnerability in the Python Code node allows authenticated users to break out of the Python sandbox environment and execute code outside the intended security boundary. This issue has been patched in version 2.4.8.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-8398-gmmx-564h | Vendor Advisory |
Configurations
History
05 Feb 2026, 20:44
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 9.9 |
| CPE | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| First Time |
N8n n8n
N8n |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-8398-gmmx-564h - Vendor Advisory |
04 Feb 2026, 17:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-04 17:16
Updated : 2026-02-05 20:44
NVD link : CVE-2026-25115
Mitre link : CVE-2026-25115
CVE.ORG link : CVE-2026-25115
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-693
Protection Mechanism Failure
