n8n Users Urged to Patch CVSS 10.0 Full System Takeover Vulnerability
ID: 1fb24320-5a89-5ac1-b5a6-2885800e8e35
STIX ID: report--1fb24320-5a89-5ac1-b5a6-2885800e8e35
Feed Name: HackRead
Threat Score
A critical authenticated remote code execution vulnerability (CVE-2026-21877, CVSS 10.0) was disclosed in the n8n automation platform: an arbitrary file write via untrusted input can lead to execution of attacker-controlled code. Versions 0.123.0 through 1.121.3 are impacted; administrators should immediately upgrade to 1.121.3+ and consider disabling the Git node and tightening admin/workflow privileges.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
