CVE-2026-56777
Last modified
CVE-2026-56777 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. EPSS estimates a 0.25% chance of exploitation in the next 30 days.
Description
n8n before 2.25.7 and 2.26.x before 2.26.2 contains an abstract syntax tree (AST) security validator bypass in the Python Code node. An authenticated user with permission to create or modify workflows containing a Python Code node can bypass the validator and access the task executor module namespace. The issue only affects self-hosted instances where the Python Task Runner is enabled; where N8N_BLOCK_RUNNER_ENV_ACCESS is configured to allow it, this can disclose environment variables accessible to the task runner process.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| N8n | N8n | < 2.25.7 |
| N8n | N8n | >= 2.26.0, < 2.26.2 |
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-jwm3-qcfw-c5ppMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-56777?
How severe is CVE-2026-56777?
How do I fix CVE-2026-56777?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-56771NewsBlur before version 14.5.0 contains a server-side reques…8.5
- CVE-2026-56772NewsBlur before 14.5.0 contains a broken access control vuln…5.3
- CVE-2026-56773Teable's v2 REST API controller lacks @Permissions metadata …8.8
- CVE-2026-56774Kanboard through 1.2.52, fixed in commit 928c68a, UserViewCo…5.4
- CVE-2026-56775n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authoriz…5.4
- CVE-2026-56776n8n before 1.123.55, 2.25.7, and 2.26.2 contains an authoriz…7.4
- CVE-2026-56778n8n before 2.25.7 and 2.26.x before 2.26.2 contains an autho…6.4
- CVE-2026-56779MaxKB before 2.10.0 contains a server-side request forgery v…6.4
- CVE-2026-5678A weakness has been identified in Totolink A7100RU 7.4cu.231…7.3
- CVE-2026-56780Modoboa before 2.9.0 contains an insecure direct object refe…7.7
- CVE-2026-56781Teable before 2026-06-15T04-43-24Z.1912 contains an improper…6.9
- CVE-2026-56782Gorse before 0.5.10 contains an authentication bypass vulner…9.8
Are you affected by CVE-2026-56777?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
