Unauthenticated second-order expression injection in n8n Form nodes
CVE-2026-27493 is a second-order expression injection vulnerability in n8n Form nodes affecting versions prior to 2.10.1, 2.9.3, and 1.123.22. Under a specific workflow configuration, an unauthenticated attacker can submit crafted form data such that a user-controlled value beginning with '=' is later interpreted by n8n as an expression rather than a literal string. This leads to unintended double evaluation of attacker-controlled content when the workflow processes the stored submission. The issue is exploitable when a Form node field interpolates data originally supplied by an unauthenticated user, such as a public form submission. On its own, the flaw enables evaluation of arbitrary n8n expressions within the available expression context; if chained with a separate expression sandbox escape vulnerability, it can be escalated to remote code execution on the n8n host.
Are you exposed to this one?
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
Impact, mitigation & remediation
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
Impact
What an attacker gets, and what they’ve been doing with it.
Mitigation
If you can’t patch tonight, do this now.
Remediation
Patch, then assume compromise.
Exploits
No public exploits tracked yet. Mallory keeps watching.
No public exploit code observed for this vulnerability.
Affected products & vendors
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
Recent activity
12 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A critical unauthenticated expression injection vulnerability in n8n Form nodes that can lead to arbitrary shell command execution (remote code execution) via double-evaluated expressions in form fields.
An unauthenticated expression evaluation flaw in n8n Form nodes that can be abused for expression injection and, when chained with a sandbox escape such as CVE-2026-27577, can lead to remote code execution on the n8n host.
A second-order expression injection (code injection) flaw in n8n Form nodes where user-supplied form fields beginning with '=' are treated as expressions and evaluated (double-evaluation), enabling unauthenticated expression execution and potential RCE when chained with an expression sandbox escape.
A second-order expression injection (code injection) flaw in n8n Form nodes where user-supplied form values beginning with '=' are treated as expressions and evaluated (double-evaluation), enabling unauthenticated expression injection and potential RCE when chained with an expression sandbox escape.
The version that knows your environment.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.