/Vulnerability Library

n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution

CVE-2026-21877
Verified

Description

n8n versions >= 0.123.0 and < 1.121.3 contain a critical authenticated remote code execution vulnerability via arbitrary file write. An authenticated user can exploit the Git node to overwrite critical files and execute untrusted code on the n8n server, potentially leading to full system compromise. The vulnerability affects both self-hosted and n8n Cloud instances.

Severity

Critical

CVSS Score

9.9

Exploit Probability

5%

Affected Product

n8n

Published Date

January 12, 2026

Template Author

s4e-io

CVE-2026-21877.yaml
9.9Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-21877
CWE ID:
cwe-434

References

https://github.com/n8n-io/n8n/security/advisories/GHSA-v364-rw7m-3263https://nvd.nist.gov/vuln/detail/CVE-2026-21877

Remediation Steps

Upgrade to n8n v1.121.3 or later. If upgrading is not immediately possible, disable the Git node and limit access for untrusted users.