#n8n


ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

Aug 20, 2026 // 23:44

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate […]

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Aug 5, 2026 // 14:55

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive […]

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

Aug 5, 2026 // 13:38

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive […]

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Jul 27, 2026 // 16:10

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security […]

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

Jul 16, 2026 // 16:37

n8n, the workflow automation platform, handed out the wrong accounts at login. On Enterprise instances configured to trust more than one external token issuer, it […]

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

Apr 17, 2026 // 13:14

Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads or fingerprint devices […]

n8n Webhooks Abused Since October 2025 to Deliver Malware via Phishing Emails

Apr 15, 2026 // 20:11

Threat actors have been observed weaponizing n8n, a popular artificial intelligence (AI) workflow automation platform, to facilitate sophisticated phishing campaigns and deliver malicious payloads or fingerprint devices […]

n8n CVE-2026-27577 and CVE-2026-27493: Sandbox Escapes and Expression Injection Fixed

Mar 11, 2026 // 19:00

Two critical vulnerabilities were recently disclosed in n8n, the popular workflow automation tool, which could allow attackers to take full control of instances or steal sensitive […]