A code injection flaw in n8n’s expression evaluation lets any authenticated user with workflow edit rights run arbitrary system commands on the host, enabling full server compromise.
Read more about Emerging Threat: (CVE-2026-27577) n8n Remote Code Execution via Workflow Expressions