Two critical vulnerabilities in the n8n AI workflow automation platform allow attackers to gain complete control over instances. n8n is considered an open source platform, although it uses a fair code license. JavaScript and Python sandbox escapesCVE-2026-1470 concerns an AST sandbox escape caused by incorrect processing of JavaScript with statements. The fixes are available in n8n versions 1.123.17, 2.4.5, and 2.5.1 for CVE-2026-1470, and versions 1.123.14, 2.3.5, and 2.4.2 for CVE-2026-0863. The n8n cloud platform has already fixed the issues.