<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #N8n</title><description>Cybersecurity articles tagged #N8n on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>n8n RCE via Expression Sandbox Escape — Mitigation Guide</title><link>https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-rce-via-expression-sandbox-escape-mitigation-guide</guid><description>Authenticated workflow editors in n8n can execute arbitrary OS commands via a sandbox escape. Update to versions 2.31.5 or 2.32.1 to mitigate this risk.</description><pubDate>Mon, 27 Jul 2026 14:38:21 GMT</pubDate><category>N8n</category><category>CVE-2026-27577</category><category>Sandbox Escape</category><category>RCE</category><category>Security Joes</category></item><item><title>n8n Token Exchange Flaw: Impersonation via `sub` Claim Bypass</title><link>https://runtimerebel.com/blog/n8n-token-exchange-flaw-impersonation-via-sub-claim-bypass</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-token-exchange-flaw-impersonation-via-sub-claim-bypass</guid><description>A critical token exchange vulnerability in n8n Enterprise allows attackers to impersonate users by leveraging `sub` claim matching across multiple external issuers…</description><pubDate>Thu, 16 Jul 2026 17:23:19 GMT</pubDate><category>N8n</category><category>Token Exchange</category><category>Authentication Bypass</category><category>Impersonation</category><category>JWT</category><category>Workflow Automation</category></item><item><title>Ivanti, Fortinet, and n8n Disclose Critical RCE and Auth Bypass Flaws</title><link>https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</link><guid isPermaLink="true">https://runtimerebel.com/blog/ivanti-fortinet-and-n8n-disclose-critical-rce-and-auth-bypass-flaws</guid><description>Ivanti, Fortinet, n8n, and SAP release urgent security patches for critical vulnerabilities including CVE-2026-5444 and CVE-2026-8043. Update systems now.</description><pubDate>Mon, 18 May 2026 13:23:34 GMT</pubDate><category>CVE-2026-8043</category><category>CVE-2026-5444</category><category>Ivanti</category><category>Fortinet</category><category>N8n</category><category>RCE</category></item><item><title>Abused n8n Webhooks Facilitate Automated Malware Delivery Since 2025</title><link>https://runtimerebel.com/blog/abused-n8n-webhooks-facilitate-automated-malware-delivery-since-2025</link><guid isPermaLink="true">https://runtimerebel.com/blog/abused-n8n-webhooks-facilitate-automated-malware-delivery-since-2025</guid><description>Threat actors are weaponizing n8n AI workflow automation webhooks to bypass email filters and distribute malware in persistent phishing campaigns.</description><pubDate>Wed, 15 Apr 2026 20:22:35 GMT</pubDate><category>N8n</category><category>Phishing</category><category>Webhooks</category><category>Malware Delivery</category><category>Automation Abuse</category></item><item><title>N8n Flaw Exploitation, Slopoly Malware, AppArmor LPE: Key Threats</title><link>https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-flaw-exploitation-slopoly-malware-apparmor-lpe-key-threats</guid><description>Analysis of recent cybersecurity threats: actively exploited N8n flaw, Slopoly malware, Linux AppArmor root privilege vulnerability, and Telus Digital breach.</description><pubDate>Fri, 13 Mar 2026 16:20:49 GMT</pubDate><category>N8n</category><category>Slopoly</category><category>Malware</category><category>AppArmor</category><category>Linux</category><category>Privilege Escalation</category><category>Data Breach</category><category>Telus Digital</category><category>Exploitation</category></item><item><title>n8n RCE via CVE-2025-68613 — CISA Flags Active Exploitation</title><link>https://runtimerebel.com/blog/n8n-rce-via-cve-2025-68613-cisa-flags-active-exploitation</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-rce-via-cve-2025-68613-cisa-flags-active-exploitation</guid><description>CISA adds CVE-2025-68613 to its KEV catalog after reports of active exploitation against n8n workflow automation instances. Patch now to prevent RCE.</description><pubDate>Thu, 12 Mar 2026 08:18:11 GMT</pubDate><category>CVE-2025-68613</category><category>N8n</category><category>RCE</category><category>CISA KEV</category><category>Expression Injection</category></item><item><title>CVE-2025-68613: n8n Improper Code Control — Actively Exploited</title><link>https://runtimerebel.com/blog/cve-2025-68613-n8n-improper-code-control-actively-exploited</link><guid isPermaLink="true">https://runtimerebel.com/blog/cve-2025-68613-n8n-improper-code-control-actively-exploited</guid><description>CISA adds CVE-2025-68613, an n8n vulnerability involving improper control of dynamically-managed code, to its KEV Catalog due to active exploitation.</description><pubDate>Wed, 11 Mar 2026 20:15:24 GMT</pubDate><category>CVE-2025-68613</category><category>N8n</category><category>KEV Catalog</category><category>Improper Control of Dynamically Managed Code Resources</category></item><item><title>n8n RCE Vulnerabilities CVE-2026-27577 and CVE-2026-27493 - Patch Now</title><link>https://runtimerebel.com/blog/n8n-rce-vulnerabilities-cve-2026-27577-and-cve-2026-27493-patch-now</link><guid isPermaLink="true">https://runtimerebel.com/blog/n8n-rce-vulnerabilities-cve-2026-27577-and-cve-2026-27493-patch-now</guid><description>Critical vulnerabilities in the n8n workflow automation platform allow unauthenticated remote code execution and sandbox escapes. Update instances immediately.</description><pubDate>Wed, 11 Mar 2026 16:26:24 GMT</pubDate><category>N8n</category><category>CVE-2026-27577</category><category>CVE-2026-27493</category><category>RCE</category><category>Workflow Automation</category></item></channel></rss>