Protection Mechanism Failure Affecting n8n-nodes-base package, versions <2.3.0


Severity

Recommended
0.0
critical
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.05% (15th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-JS-N8NNODESBASE-15225503
  • published5 Feb 2026
  • disclosed4 Feb 2026
  • creditMarcoPoloPie, c0rydoras

Introduced: 4 Feb 2026

NewCVE-2026-25115  (opens in a new tab)
CWE-693  (opens in a new tab)

How to fix?

Upgrade n8n-nodes-base to version 2.3.0 or higher.

Overview

n8n-nodes-base is a Base nodes of n8n

Affected versions of this package are vulnerable to Protection Mechanism Failure via the Python Code node. An attacker can execute arbitrary code outside the intended security boundary by leveraging authenticated access and enabling Task Runners with Python support. This is only exploitable if Task Runners are enabled (N8N_RUNNERS_ENABLED=true), Python support is enabled (N8N_PYTHON_ENABLED=true), and the Code Node is enabled (default: true).

Workaround

This vulnerability can be mitigated by disabling the Code Node via the NODES_EXCLUDE environment variable or running Task Runners in external mode to isolate untrusted code execution in a separate sidecar container.

References

CVSS Base Scores

version 4.0
version 3.1