CVE-2026-21877 is a critical remote code execution (RCE) vulnerability affecting n8n, an open-source workflow automation platform, in versions 0.121.2 and below. An authenticated attacker can exploit this flaw to execute malicious code, leading to full system compromise of both self-hosted and n8n Cloud instances. With a CVSS score of 9.9 (CRITICAL), this vulnerability is easily exploitable over the network with low privileges and no user interaction, resulting in complete confidentiality, integrity, and availability impact. While not yet listed in CISA's KEV catalog, exploit intelligence indicates available Nuclei templates and significant community discussion and media coverage, suggesting a high likelihood of future exploitation. Upgrading to version 1.121.3 or later is strongly recommended, though disabling the Git node and limiting untrusted user access can offer partial mitigation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.123.0, < 1.121.3CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 1.0 Bluesky, 0.5 Mastodon, and 1.6 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.