Skip to content

Known CVE

n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution

n8n versions >= 0.123.0 and < 1.121.3 contain a critical authenticated remote code execution vulnerability via arbitrary file write. An authenticated user can exploit the Git node to overwrite critical files and execute untrusted code on the n8n server, potentially leading to full system compromise. The vulnerability affects both self-hosted and n8n Cloud instances.

CVE-2026-21877

Critical2026CVSS 9.9CWE-434

cve2026 · n8n · workflow · rce · authenticated · passive

Verified scans run this check after you prove you own the site.

All known CVEsView the checks catalogNational Vulnerability Database

Scan a website