PT-2026-6100 · N8N · N8N

Berkdedekarginoglu

·

Published

2026-02-04

·

Updated

2026-02-05

·

CVE-2026-21893

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions n8n versions 0.187.0 through 1.120.2
Description n8n is a workflow automation platform. A command injection issue was identified in the community package installation functionality. This allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. The issue was present in versions from 0.187.0 up to, but not including, 1.120.3. The vulnerability allows for potential privilege escalation from administrator to root. The vulnerable functionality involves the package installation process, lacking sufficient input sanitization.
Recommendations Update to version 1.120.3 or later.

Exploit

Fix

LPE

OS Command Injection

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-21893
GHSA-7C4H-VH2M-743M

Affected Products

N8N