n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution
CVE-2026-21877
Verified
Description
n8n versions >= 0.123.0 and < 1.121.3 contain a critical authenticated remote code execution vulnerability via arbitrary file write. An authenticated user can exploit the Git node to overwrite critical files and execute untrusted code on the n8n server, potentially leading to full system compromise. The vulnerability affects both self-hosted and n8n Cloud instances.
Severity
Critical
CVSS Score
9.9
Exploit Probability
5%
Affected Product
n8n
Published Date
January 12, 2026
Template Author
s4e-io
CVE-2026-21877.yaml
9.9Score
CVSS Metrics
CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
CVE ID:
cve-2026-21877
CWE ID:
cwe-434
Remediation Steps
Upgrade to n8n v1.121.3 or later. If upgrading is not immediately possible, disable the Git node and limit access for untrusted users.