n8n Workflow-to-RCE: 321 Exposed Servers and a 9.9 Sandbox Escape
Leaked tokens, a 9.9 Python flaw, and 321 live servers show why self-hosted n8n needs lockdown On August 5, 2026, The Hacker News reported that leaked n8n API tokens exposed hundreds of live automation instances. Researchers found 321 publicly reachable servers still accepting credentials accidentally committed to GitHub. If you self-host n8n, this is not … Read more
Automation is powerful. But the moment your workflows start moving real data—customer details, API keys, internal notifications—another question appears.