CVE-2026-0863 | n8n up to 1.123.13/2.3.4/2.4.1 python-task-executor eval injection (jfsa-2026-001651 / EUVD-2026-3171)
A vulnerability was found in n8n up to 1.123.13/2.3.4/2.4.1. It has been rated as critical. Affected is an unknown function of the component python-task-executor. The manipulation leads to improper neutralization of directives in dynamically evaluated code.
This vulnerability is uniquely identified as CVE-2026-0863. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.