- Description
- n8n is an open source workflow automation platform. In versions 0.121.2 and below, an authenticated attacker may be able to execute malicious code using the n8n service. This could result in full compromise and can impact both self-hosted and n8n Cloud instances. This issue is fixed in version 1.121.3. Administrators can reduce exposure by disabling the Git node and limiting access for untrusted users, but upgrading to the latest version is recommended.
- Source
- security-advisories@github.com
- NVD status
- Analyzed
- Products
- n8n
CVSS 3.1
- Type
- Secondary
- Base score
- 9.9
- Impact score
- 6
- Exploitability score
- 3.1
- Vector string
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Severity
- CRITICAL
- security-advisories@github.com
- CWE-94
- Hype score
- Not currently trending
csirt_it: La Settimana Cibernetica del 01 febbraio 2026 🔹 aggiornamenti per molteplici prodotti 🔹Ivanti: rilevate due nuove vulnerabilità, di cui una di tipo zero-day ⚠️ #EPSS: 🔹Ivanti: CVE-2025-22467 🔹n8n: CVE-2026-21877 🔗https://t.co/LJ96VJjGgo https://t.
@Vulcanux_
2 Feb 2026
78 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
La Settimana Cibernetica del 01 febbraio 2026 🔹 aggiornamenti per molteplici prodotti 🔹Ivanti: rilevate due nuove vulnerabilità, di cui una di tipo zero-day ⚠️ #EPSS: 🔹Ivanti: CVE-2025-22467 🔹n8n: CVE-2026-21877 🔗https://t.co/pHK5h3Jjiz https://t.co/wuilz7q
@csirt_it
2 Feb 2026
310 Impressions
1 Retweet
3 Likes
0 Bookmarks
0 Replies
0 Quotes
IMPORTANT: Upgrade your self hosted n8n! All supported versions prior to 2.0.0 are affected. CVE-2025-68613 https://t.co/v5KUleCXlR CVE-2025-68668 https://t.co/PW7rPZkWK6 CVE-2026-21858 https://t.co/GK2twlNwnR CVE-2026-21877 https://t.co/DLDO9vYlfa
@igz4rd
28 Jan 2026
47 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
Sicherheitsdesaster bei Automatisierungsplattform n8n (CVE-2026-21877, CVE-2025-68668, CVE‑2026‑21858) | Borns IT- und Windows-BlogBorns IT- und Windows-Blog https://t.co/JDnfmW6STY
@ItE2u
10 Jan 2026
49 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
12 new OPEN, 15 new PRO (12 + 3) ZPHP, itagent RMM, several CVEs (CVE-2025-15356, CVE-2025-15471, CVE-2026-21877) and more. https://t.co/cgfguZ6E8F
@ET_Labs
7 Jan 2026
226 Impressions
2 Retweets
2 Likes
0 Bookmarks
0 Replies
0 Quotes
[
{
"nodes": [
{
"cpeMatch": [
{
"criteria": "cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*",
"matchCriteriaId": "ECD7E4E7-DB69-4A3C-B8AE-655D0081624D",
"versionEndExcluding": "1.121.3",
"versionStartIncluding": "0.123.0",
"vulnerable": true
}
],
"negate": false,
"operator": "OR"
}
]
}
]