logo

CVSS 10.0 Alert: Critical n8n Flaw CVE-2026-21877 Grants Total Control

ID: c546daeb-ac7a-582c-b710-c3d3db3a7a63

STIX ID: report--c546daeb-ac7a-582c-b710-c3d3db3a7a63

Feed Name: securityonline.info

Threat Score
90/100

Date Published: 2026-01-07

Date Updated: 2026-04-22

Author: Ddos

...
...

n8n disclosed a critical Remote Code Execution vulnerability (CVE-2026-21877, CVSS 10.0) that allows an authenticated user to perform arbitrary file writes and execute untrusted code, potentially leading to full compromise of both self-hosted and n8n Cloud instances; the issue is fixed in n8n 1.121.3, and immediate mitigations include upgrading or disabling the Git node and restricting access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.