Fetching from the wire…
Top 5 · 2026-03-25 · source-backed
If you run n8n, stop reading and go patch. Right now.
Pillar Security researcher Eilon Cohen disclosed four critical vulnerabilities in n8n, the open-source workflow automation platform with 181K GitHub stars. The worst one, CVE-2026-27493 (CVSS 9.5), allows unauthenticated expression injection via public Form nodes. An attacker can execute arbitrary shell commands through a public contact form with no authentication. No credentials needed. No user interaction. Just a public n8n form and a POST request.
The other three CVEs are almost as bad. CVE-2026-27577 (CVSS 9.4): expression sandbox escape via an AST rewriter flaw. CVE-2026-27495 (CVSS 9.4): JavaScript Task Runner sandbox code injection. CVE-2026-27497 (CVSS 9.4): Merge node SQL query exploitation. All patched in n8n 2.10.1, 2.9.3, and 1.123.22.
CISA's KEV remediation deadline for the related CVE-2025-68613 is literally today, March 25. There are 71,537 exposed n8n instances observable worldwide. If yours is one of them and you haven't patched, you're running an unauthenticated remote code execution server on the open internet.
I keep seeing this pattern with workflow automation platforms. They're designed to be easy to deploy, which means they often end up exposed without proper network segmentation or authentication hardening. n8n's fair-code license makes it popular with small teams and solo builders who may not have dedicated security staff reviewing CVE lists. The Form node bug is especially concerning because it turns a feature designed for public input into an attack vector. Anyone who set up a public n8n form for lead capture, customer feedback, or intake workflows just handed unauthenticated RCE to the internet.
Patch to 2.10.1 or later. Audit your public-facing n8n forms. If you can't patch immediately, disable all public Form nodes until you can.
Each link below shares sources, entities, or timing with this story.
The Model Context Protocol has a security problem that's no longer theoretical — it's statistical. Between January and February 2026, researchers filed 30+ CVEs against MCP servers, clients, and infrastructure. One package with nearly 500,000 downloads carried a CVSS 9.6 RCE....
CVE-2026-33017 is an unauthenticated RCE (CVSS ~9.8) in Langflow's public flow-build endpoint. Attackers weaponized it within 20 hours of disclosure, before any public PoC, by reverse-engineering the advisory text. Exploitation systematically exfiltrated OpenAI, Anthropic, and...
OX Security disclosed a systemic vulnerability on June 16 in core Model Context Protocol implementations that enables arbitrary command execution, exposing API keys, internal databases, and chat histories on any vulnerable MCP host. This isn't one bad server. It's a protocol-l...
Cisco Talos uncovered "UAT-10608", a credential harvesting campaign exploiting CVE-2025-55182 (CVSS 10.0) in React Server Components and Next.js App Router. 766 servers worldwide. 24 hours. Post-compromise, 91.5% of hosts leaked database credentials and 78.2% exposed SSH priva...
Six CVEs traced to AI-generated code in January. Fifteen in February. Thirty-five in March. Infosecurity Magazine reports the numbers, tracked by Georgia Tech's SSLab through their "Vibe Security Radar" project running since May 2025. The acceleration is clear and there's no s...
Two AI toolchain CVEs hit CISA's Known Exploited Vulnerabilities catalog this week, and the attack chain connecting them is the kind of thing that should change how you think about supply chain trust. CVE-2026-33017: Langflow, the popular agent workflow builder, has an unauthe...
MindPattern daily
One email a day at 7 AM. Sources and a take on every story. Unsubscribe anytime.