n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with permission to create or modify workflows containing a Python Code Node could escape the sandbox and achieve arbitrary code execution on the task runner container. This issue only affects instances where the Python Task Runner is enabled. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.
References
| Link | Resource |
|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-44v6-jhgm-p3m4 | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
06 May 2026, 18:05
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:n8n:n8n:2.18.0:*:*:*:enterprise:node.js:*:* cpe:2.3:a:n8n:n8n:*:*:*:*:enterprise:node.js:*:* |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
| First Time |
N8n n8n
N8n |
|
| References | () https://github.com/n8n-io/n8n/security/advisories/GHSA-44v6-jhgm-p3m4 - Vendor Advisory |
04 May 2026, 19:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-05-04 19:16
Updated : 2026-05-06 18:05
NVD link : CVE-2026-42234
Mitre link : CVE-2026-42234
CVE.ORG link : CVE-2026-42234
JSON object : View
Products Affected
n8n
- n8n
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')
