CVE-2026-21858

Published Jan 8, 2026

Last updated 8 months ago

CVSS critical 10.0
n8n
Ni8mare
Chat GPT
Cloud

Overview

AI description

Automated description summarized from trusted sources.

CVE-2026-21858, dubbed "Ni8mare" by Cyera Research Labs, is a critical vulnerability found in the n8n workflow automation platform. The flaw stems from a "Content-Type confusion" issue within the `formWebhook()` function, which is responsible for handling form submissions. This function fails to adequately verify that the incoming HTTP request's `Content-Type` header is set to "multipart/form-data" before processing files. This oversight allows an unauthenticated attacker to manipulate the `req.body.files` object by sending specially crafted requests. By exploiting this, an attacker can achieve arbitrary file reads from the n8n server and potentially escalate their access to execute arbitrary commands on the underlying system. The vulnerability affects n8n versions up to and including 1.65.0 and was addressed in version 1.121.0, released on November 18, 2025.

Description
n8n is an open source workflow automation platform. Versions starting with 1.65.0 and below 1.121.0 enable an attacker to access files on the underlying server through execution of certain form-based workflows. A vulnerable workflow could grant access to an unauthenticated remote attacker, resulting in exposure of sensitive information stored on the system and may enable further compromise depending on deployment configuration and workflow usage. This issue is fixed in version 1.121.0.
Source
security-advisories@github.com
NVD status
Analyzed
Products
n8n

Risk scores

CVSS 3.1

Type
Secondary
Base score
10
Impact score
5.8
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Severity
CRITICAL

Weaknesses

security-advisories@github.com
CWE-20

Social media

Hype score
Not currently trending
  1. 「パッチが出た」と「直った」は別の日付です。 CVSS10.0のCVE-2026-21858。Webhookのファイル確認漏れが原因です。修正版は2025年11月公開。 海外調査(2026年1月時点)では世界2万6,512台が晒されていました。情シス兼

    @n8nFlowMaster

    12 Aug 2026

    73 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    1 Quote

  2. #HermesAgent こんな使い方もされているのか。しかし、バレ方が間抜け感。 中国語圏の攻撃者、DeepSeekとHermes Agentで自律型 サイバー攻撃を実行 Unit 42が7件の脆弱性 悪用を確認(CVE-2026-33017,CVE-2026-21858/CVE-2025-68613)

    @kinneko

    5 Aug 2026

    283 Impressions

    0 Retweets

    3 Likes

    1 Bookmark

    0 Replies

    0 Quotes

  3. Unit 42 recovered logs of a @deepseek_ai-driven Hermes Agent that autonomously scanned and exploited targets via Telegram. The agent evaluated CVE-2026-33017 in Langflow and CVE-2026-21858 plus CVE-2025-68613 in n8n, yet failed on every host because required configurations were

    @WorldCyberNewsX

    4 Aug 2026

    6 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  4. 中国語圏の攻撃者、DeepSeekとHermes Agentで自律型 サイバー攻撃を実行 Unit 42が7件の脆弱性 悪用を確認(CVE-2026-33017,CVE-2026-21858/CVE-2025-68613) https://t.co/TW31twyRG4 #セキュリティ対策Lab #security #securitynews #cyberattack

    @securityLab_jp

    4 Aug 2026

    182 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  5. Top 5 Trending CVEs: 1 - CVE-2026-27522 2 - CVE-2026-3055 3 - CVE-2025-58718 4 - CVE-2026-20963 5 - CVE-2026-21858 #cve #cvetrends #cveshield #cybersecurity https://t.co/4Fua3CAN6W

    @CVEShield

    26 Mar 2026

    238 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. n8n CVE-2025-68613 + CVE-2026-21858 chain is getting active exploitation. CISA KEV only lists 68613 — but 21858 (unauth RCE) is the one doing damage. 14K+ exposed instances per Shodan. Our feeds have tracked 2,200+ items on this. Self-hosted n8n: patch both, now.

    @CybrPulse

    25 Mar 2026

    115 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  7. New research shows a gap in CISA KEV for n8n. CVE-2025-68613 can be chained with CVE-2026-21858 (not in KEV) for unauthenticated RCE, and exploitation is already happening. 14K+ exposed instances and links to MuddyWater suggest the risk is understated: https://t.co/dgirWHh65P

    @VulnCheckAI

    20 Mar 2026

    684 Impressions

    1 Retweet

    2 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  8. n8n Vulnerability Analysis: CVE-2025-68613, CVE-2026-21858, CVE-2026-25049 https://t.co/OkUxRBFKB6 #cyber #threathunting #infosec

    @blueteamsec1

    13 Mar 2026

    917 Impressions

    0 Retweets

    2 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  9. New TALON report: Critical vulnerabilities in #n8n workflow automation. CVE-2025-68613 and CVE-2026-21858 could be chained to increase security risk. 👉 Learn more: https://t.co/GlqBXbZB0N https://t.co/y1Jd78MfJF

    @S2W_Official

    11 Feb 2026

    147 Impressions

    0 Retweets

    1 Like

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2026-21858+ CVE-2025-68613: n8n Ni8mare - Full Chain Exploit Unauthenticated to Root RCE: - LFI via Content-Type confusion Read/proc/self/environ to find HOME - Steal encryption key + database - Forge admin WT token - Expression injection sandbox bypass RCE as root ht

    @Danodi_j6

    6 Feb 2026

    77 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  11. IMPORTANT: Upgrade your self hosted n8n! All supported versions prior to 2.0.0 are affected. CVE-2025-68613 https://t.co/v5KUleCXlR CVE-2025-68668 https://t.co/PW7rPZkWK6 CVE-2026-21858 https://t.co/GK2twlNwnR CVE-2026-21877 https://t.co/DLDO9vYlfa

    @igz4rd

    28 Jan 2026

    47 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  12. RCE Chain en n8n: Del Zero-Access al Root (CVE-2026-21858 + CVE-2025-68613) #ciberseguridad #hacking https://t.co/OnISVZ3vPm

    @FredyBahenaM

    11 Jan 2026

    81 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    1 Reply

    0 Quotes

  13. Critical RCE vulns hitting hard: Trend Micro Apex Central (CVE-2025-69258 PoC out) & HPE OneView (CVE-2025-37164 in CISA KEV). Plus, n8n’s “Ni8mare” (CVE-2026-21858, CVSS 10) fueling cloud intrusions. #CyberSecurity

    @huntthethreat

    11 Jan 2026

    0 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  14. CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain https://t.co/HLIqfT3D4I #exploit #exploitation #cve #cybersecurity #informationsecurity #ai https://t.co/YtBwvCMR9R

    @blackstormsecbr

    10 Jan 2026

    144 Impressions

    1 Retweet

    3 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  15. CVE-2026-21858 + CVE-2025-68613: n8n Ni8mare - Full Chain Exploit Unauthenticated to Root RCE: - LFI via Content-Type confusion - Read /proc/self/environ to find HOME - Steal encryption key + database - Forge admin JWT token - Expression injection sandbox bypass - RCE as root ht

    @HackingTeam777

    9 Jan 2026

    10183 Impressions

    45 Retweets

    218 Likes

    97 Bookmarks

    5 Replies

    2 Quotes

  16. C'est un beau début d'année pour la FrenchTech avec : 💥 Vulns CVE-2026-21858 et CVE-2025-68613 n8n par @Chocapikk 💥 Vuln Livewire CVE-2025-54068* par @_Worty et @_remsio_ Bravo à vous 🎉 et bonne année 2026 😄 *allez.... fin 2025 c'est presque début 2026 😅

    @mynameisv_

    9 Jan 2026

    424 Impressions

    0 Retweets

    6 Likes

    0 Bookmarks

    4 Replies

    0 Quotes

  17. CVE-2026-21858 + CVE-2025-68613: n8n Ni8mare - Full Chain Exploit Unauthenticated to Root RCE: - LFI via Content-Type confusion - Read /proc/self/environ to find HOME - Steal encryption key + database - Forge admin JWT token - Expression injection sandbox bypass - RCE as root ht

    @Hackervidya

    8 Jan 2026

    68 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  18. CVE-2026-21858 + CVE-2025-68613: n8n Ni8mare - Full Chain Exploit Unauthenticated to Root RCE: - LFI via Content-Type confusion - Read /proc/self/environ to find HOME - Steal encryption key + database - Forge admin JWT token - Expression injection sandbox bypass - RCE as root ht

    @Chocapikk_

    7 Jan 2026

    36101 Impressions

    146 Retweets

    596 Likes

    318 Bookmarks

    8 Replies

    8 Quotes

Configurations