Known CVE
n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution
n8n versions >= 0.123.0 and < 1.121.3 contain a critical authenticated remote code execution vulnerability via arbitrary file write. An authenticated user can exploit the Git node to overwrite critical files and execute untrusted code on the n8n server, potentially leading to full system compromise. The vulnerability affects both self-hosted and n8n Cloud instances.
CVE-2026-21877
Critical2026CVSS 9.9CWE-434
cve2026 · n8n · workflow · rce · authenticated · passive
Verified scans run this check after you prove you own the site.
All known CVEsView the checks catalogNational Vulnerability Database
Scan a website