Critical n8n Vulnerability Allows Authenticated Remote Code Execution
ID: 868ee8f4-ce6c-5a7d-ba07-cbec1fbdc6f7
STIX ID: report--868ee8f4-ce6c-5a7d-ba07-cbec1fbdc6f7
Feed Name: GBHackers
Threat Score
A critical authenticated RCE vulnerability (CVE-2026-21877, CVSS 9.9) was disclosed in n8n's handling of workflow nodes—particularly the Git node—allowing authenticated users to execute arbitrary code on the host; the issue has been patched in n8n v1.121.3, and administrators are advised to upgrade immediately or apply mitigations (restrict access, disable the Git node) until patched.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
