
[CIVN-2026-0006] Remote Code Execution vulnerability in n8n
—–BEGIN PGP SIGNED MESSAGE—–
Hash: SHA256
Remote Code Execution vulnerability in n8n
Indian – Computer Emergency Response Team (https://www.cert-in.org.in)
Severity Rating: CRITICAL
Software Affected
n8n Workflow Automation Platform versions prior to 1.121.0
Overview
A critical vulnerability has been reported in n8n Workflow Automation Platform which could be exploited by an unauthenticated attacker to gain unauthorized access, disclose sensitive information and potentially enable further compromise of the targeted system.
Target Audience:
System administrators, DevOps teams and organizations deploying or managing n8n Workflow Automation Platform.
Risk Assessment:
High risk of unauthenticated arbitrary code execution and system compromise.
Impact Assessment:
Potential for sensitive data exposure and unauthorized access.
Description
n8n is an open-source workflow automation platform used to design, execute and manage automated workflows that integrate applications, services and APIs.
A critical vulnerability exists in n8n due to improper handling of webhook request. An attacker can exploit this vulnerability by triggering of certain form-based workflows.
Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access, disclose sensitive information and potentially enable further compromise of the targeted system.
Solution
Apply appropriate updates as mentioned by the vendor:
https://n8n.io/legal/security/
Vendor Information
n8n Workflow Automation Platform
https://n8n.io/
References
https://n8n.io/legal/security/
https://github.com/n8n-io/n8n/security/advisories/GHSA-v4pr-fm98-w9pg
CVE Name
CVE-2026-21858
– —
Thanks and Regards,
CERT-In
Incident Response Help Desk
e-mail: incident@cert-in.org.in
Phone: +91-11-22902657
Toll Free Number: 1800-11-4949
Toll Free Fax : 1800-11-6969
Web: http://www.cert-in.org.in
PGP Fingerprint: A768 083E 4475 5725 B81A A379 2156 C0C0 B620 D0B4
PGP Key information:
https://www.cert-in.org.in/s2cMainServlet?pageid=CONTACTUS
Postal address:
Indian Computer Emergency Response Team (CERT-In)
Ministry of Electronics and Information Technology
Government of India
Electronics Niketan
6, C.G.O. Complex
New Delhi-110 003
—–BEGIN PGP SIGNATURE—–
iQIzBAEBCAAdFiEE6r4Iam/Ey0c/KakL3jCgcSdcys8FAmlhGO4ACgkQ3jCgcSdc
ys92mw//eP6Xx0spI7gnN2xi+VPjZH4uCFvGUE65uwMz+0Dbbm3Ge0kYrLp4OXFB
jpWgHMlMawuM9RysrCNi3b/zwB6g5PdFWubLTLGOhUYs3/TDFmLWiJHErl+jHtqw
t7cfbI8ui+tvb1i6Ww8RCRSo4jcEY3Xv8W/o+khgLNc+6TbGpBskuXDXVrURtPSv
tFnlUNwuj/n1tKxqIo/759PDGhj5Foq0TdBBYdHQot9BGbTUYWuX9US71Ueq6Dx6
zK9RoNtrU7ujuCmxFdMksM0u2blAIODAlXFoWZ/pj77QsfW0QQmTS0xyWGqFhTZb
oz3T7n0N4pSoliAlw9ofshhI/R6am4IzGUppLUslB3uI/2ZOFWPWiMoMLDluEb+z
gahu7OyEUy1kDy0/o8J2Dn3lcopiSwJrMYJSnEwKoySIB3LolVMgmv+G7ctwchhp
MM8fJkx5Gf3i2i2GREq0CK3cscFG2vpUXslAp3VqepIBn34VRX2Oh4xpQIqIddtx
GDtGtzodVPbPzVs85SsF9sHrTR/2bNthTSSNatCaXAMF0741Enwmut6ics/B9wVQ
6aRf8PZtGZWoMKQtAonu9K5nZmu6xfqeiSwoF2dv5h3tPZOw+gVhM92kaG5lqRqH
es5OA9wqoOC/IwYM50lMSMkubV8CXBGVmmtWdyTnNThxvQwjZvg=
=FP9c
—–END PGP SIGNATURE—–


