CVE-2026-27497 | n8n-io n8n up to 1.123.21/2.9.2/2.10.0 Environment Variable NODES_EXCLUDE code injection (GHSA-wxx7-mcgf-j869)
A vulnerability was found in n8n-io n8n up to 1.123.21/2.9.2/2.10.0. It has been declared as critical. This impacts an unknown function of the component Environment Variable Handler. Such manipulation of the argument NODES_EXCLUDE leads to code injection.
This vulnerability is documented as CVE-2026-27497. The attack can be executed remotely. There is not any exploit available.
It is recommended to upgrade the affected component.