CVE-2026-65590N8n · N8n
Vulnerability data via NVD (ingested)
n8n before 2.29.8 and 2.30.x before 2.30.1 does not enforce shell sandbox restrictions on Linux and Windows in the @n8n/computer-use package (sandboxing was applied only on macOS). Shell commands executed by the tool run without any filesystem or network restrictions, allowing unrestricted access to the host filesystem and network from within the computer-use agent process. This issue only affects deployments where the @n8n/computer-use package is explicitly installed and running; standard n8n installations are not affected.
External references
Search for exposed instances
Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).
vuln:CVE-2026-65590product:"N8n N8n"http.html:"N8n"More intel sources (5)
vuln:CVE-2026-65590vulnerabilities.cve_id: CVE-2026-65590CVE-2026-65590CVE-2026-65590"CVE-2026-65590" exploit -site:nvd.nist.gov