SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65590

CRITICAL · CVSS 9.8 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

The vulnerability affects the @n8n/computer-use package in n8n versions prior to 2.29.8 and 2.30.x before 2.30.1 on both Windows and Linux systems, where shell commands can be executed without proper sandboxing restrictions. This allows attackers to gain unrestricted access to the host filesystem and network, posing a critical risk to sensitive data and system integrity. Organizations using the affected package should prioritize immediate updates to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65590
Severity
CRITICAL
CVSS
9.8
EPSS
0.32%
Windows Linux

Original NVD Description

n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.

Related CVEs

Other vulnerabilities affecting the same vendor(s)