PT-2026-6100 · N8N · N8N
Berkdedekarginoglu
·
Published
2026-02-04
·
Updated
2026-02-05
·
CVE-2026-21893
CVSS v4.0
9.4
Critical
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
n8n versions 0.187.0 through 1.120.2
Description
n8n is a workflow automation platform. A command injection issue was identified in the community package installation functionality. This allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. The issue was present in versions from 0.187.0 up to, but not including, 1.120.3. The vulnerability allows for potential privilege escalation from administrator to root. The vulnerable functionality involves the package installation process, lacking sufficient input sanitization.
Recommendations
Update to version 1.120.3 or later.
Exploit
Fix
LPE
OS Command Injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N8N