Remote Code Execution Vulnerabilities in n8n Node.js Package

Remote Code Execution Vulnerabilities in n8n Node.js Package

First seen 14 Feb 2026, 07:09 UTC Tenable 25.3

Article Content

Browse articles
ThreatCluster

The n8n Node.js Package is affected by multiple remote code execution vulnerabilities. Versions 2.x prior to 2.4.8 and 2.x prior to 2.5.2 are impacted, along with versions below 1.123.17. Users of the affected packages should apply patches to mitigate these vulnerabilities.

Timeline

2026-02-13
Tenable published vulnerabilities for n8n Node.js Package
Recent
Users advised to patch affected n8n Node.js Package versions