Critical n8n Flaws Enable Server Takeover and Credential Theft

Two critical vulnerabilities in the n8n workflow platform allow unauthenticated attackers to run commands and escape the sandbox. Both cloud and self-hosted instances are affected, and attackers could extract all credentials stored in n8n’s database, exposing connected systems.

Part of the PlainSec briefing for 2026-03-13

Sources