logo

n8n Users Urged to Patch CVSS 10.0 Full System Takeover Vulnerability

ID: 1fb24320-5a89-5ac1-b5a6-2885800e8e35

STIX ID: report--1fb24320-5a89-5ac1-b5a6-2885800e8e35

Feed Name: HackRead

Threat Score
80/100

Date Published: 2026-01-08

Date Updated: 2026-04-22

Author: Deeba Ahmed

...
...

A critical authenticated remote code execution vulnerability (CVE-2026-21877, CVSS 10.0) was disclosed in the n8n automation platform: an arbitrary file write via untrusted input can lead to execution of attacker-controlled code. Versions 0.123.0 through 1.121.3 are impacted; administrators should immediately upgrade to 1.121.3+ and consider disabling the Git node and tightening admin/workflow privileges.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.