Back Morningstar Pillar Security Discovered Critical Flaw in n8n Exposing Hundreds of Thousands of ...
Pillar Security Discovered Critical Flaw in n8n Exposing Hundreds of Thousands of Enterprise AI Systems to Complete Takeover
Pillar Security discovers two critical vulnerabilities (CVSS 10.0) in popular workflow automation platform affecting hundreds of thousands of deployments – enabling attackers to decrypt stored credentials, hijack AI pipelines, and compromise multi-tenant n8n cloud enterprise environments
Pillar Security , a pioneering company in AI security, today disclosed critical sandbox escape vulnerabilities in n8n, the open-source workflow automation platform powering hundreds of thousands of enterprise deployments worldwide. The vulnerabilities, assigned a maximum CVSS score of 10.0 (Critical), allowed any authenticated user to achieve complete server control and steal every stored credential, API key, and secret on both self-hosted and cloud instances.
This discovery is particularly significant given n8n's role as the connective tissue of enterprise AI infrastructure, orchestrating agentic workflows and LLM-powered applications. The platform has become essential for organizations deploying AI at scale, making the exposure of AI API keys, vector database credentials, and proprietary prompts especially concerning.
"What makes these vulnerabilities particularly dangerous is the combination of ease of exploitation and the high-value targets they expose," said Eilon Cohen, AI Security Researcher at Pillar Security. "If you can create a workflow in n8n, you can own the server. For attackers, this means access to OpenAI keys, Anthropic credentials, AWS accounts, and the ability to intercept or modify AI interactions in real-time – all while the workflows continue functioning normally."
The vulnerabilities affect all n8n users prior to version 2.4.0, including:
The research identified several high-impact attack patterns:
Pillar Security strongly recommends the following immediate actions:
Following responsible disclosure practices, Pillar Security reported both vulnerabilities to n8n with security guidance on code fixes, who responded rapidly with patches during the holiday season, releasing version 2.4.0 with fixes in January 2026.
Link to full technical report :
Pillar Security is a leading AI security platform, providing companies with full visibility and control to build and run secure AI systems. Founded by experts in offensive and defensive cybersecurity, Pillar secures the entire AI lifecycle, from development to deployment – through AI Discovery, AI Security Posture Management (AI-SPM), AI Red Teaming, and Adaptive Runtime Guardrails.
Pillar empowers organizations to prevent data leakage, neutralize AI-specific threats, and comply with evolving regulations. The platform is trusted by global enterprises and serves customers analyzing millions of prompts monthly and scanning tens of thousands of code repositories.
Powered by real-world threat intelligence and advanced adversarial research, Pillar leverages insights from analyzing millions of AI interactions, scanning tens of thousands of repositories, and continuously testing production AI systems to deliver precise threat detection, adaptive protection, and validated security assessments.
Media Taylor Hadley Pillar@cyberriskalliance.com 978-877-2113
View source version on businesswire.com:
The articles, information, and content displayed on this webpage may include materials prepared and provided by third parties. Such third-party content is offered for informational purposes only and is not endorsed, reviewed, or verified by Morningstar.
Morningstar makes no representations or warranties regarding the accuracy, completeness, timeliness, or reliability of any third-party content displayed on this site. The views and opinions expressed in third-party content are those of the respective authors and do not necessarily reflect the views of Morningstar, its affiliates, or employees.
Morningstar is not responsible for any errors, omissions, or delays in this content, nor for any actions taken in reliance thereon. Users are advised to exercise their own judgment and seek independent financial advice before making any decisions based on such content. The third-party providers of this content are not affiliated with Morningstar, and their inclusion on this site does not imply any form of partnership, agency, or endorsement.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
