n8n Workflow-to-RCE: 321 Exposed Servers and a 9.9 Sandbox Escape

n8n security vulnerabilities

Leaked tokens, a 9.9 Python flaw, and 321 live servers show why self-hosted n8n needs lockdown On August 5, 2026, The Hacker News reported that leaked n8n API tokens exposed hundreds of live automation instances. Researchers found 321 publicly reachable servers still accepting credentials accidentally committed to GitHub. If you self-host n8n, this is not … Read more

n8n API Token Leak Exposes Hundreds of Automation Servers

n8n API token leak

GitGuardian discovered thousands of exposed n8n API tokens in public GitHub commits, allowing access to hundreds of live automation servers without exploiting a single software vulnerability. Your automation platform was supposed to save time. It connects your databases to your CRM. It triggers AI agents when customers complain. It moves data between your cloud provider … Read more

CVE-2026-59208 | n8n Enterprise Authentication Flaw Could Allow Cross-Issuer Account Takeover

CVE-2026-59208

A token exchange vulnerability in n8n Enterprise lets valid JWTs from one trusted identity provider authenticate as users from another issuer when subject identifiers collide. Imagine typing no password at all. None. Zero keystrokes. Yet suddenly, you’re inside someone else’s account. Their workflows. Their data. Their entire digital workspace, laid bare before you. That is … Read more

JadePuffer: The First AI-Driven Ransomware Attack Explained

AI-driven ransomware

What if the hacker attacking your systems never slept, never paused, and fixed its own mistakes in 31 seconds flat? Meet JadePuffer. The Sysdig Threat Research Team just documented something terrifying: the first ransomware operation run entirely by a large language model. No human at the keyboard. No coffee breaks. Just an AI agent methodically … Read more