n8n Warns of CVSS 10.0 RCE Vulnerability Affecting Self-Hosted and Cloud Versions
嗯,用户让我总结一篇文章的内容,控制在一百个字以内,而且不需要用“文章内容总结”之类的开头。首先,我需要仔细阅读这篇文章,抓住关键点。 文章主要讲的是开源平台n8n发现了一个最高级别的安全漏洞,CVE-2026-21877,CVSS评分10.0。这个漏洞可能导致认证的远程代码执行,影响自托管和云实例。受影响的版本是>=0.123.0且<1.121.3,已经修复在1.121.3版本中。研究人员Théo Lelasseux发现了这个漏洞。 用户可能需要的是一个简洁明了的总结,用于快速了解情况。所以我要把主要信息浓缩进去:漏洞名称、严重程度、影响范围、修复版本以及建议措施。 最后,确保语言简洁,不超过一百字,并且直接描述内容,不加任何开头。 </think> 开源工作流自动化平台n8n警告称发现最高级别安全漏洞CVE-2026-21877,可能导致认证远程代码执行。该漏洞影响自托管和云实例,已修复于版本1.121.3。建议用户升级或采取临时措施限制暴露。 2026-1-7 11:26:0 Author: thehackernews.com(查看原文) 阅读量:2 收藏

Vulnerability / Cloud Security

Open-source workflow automation platform n8n has warned of a maximum-severity security flaw that, if successfully exploited, could result in authenticated remote code execution (RCE).

The vulnerability, which has been assigned the CVE identifier CVE-2026-21877, is rated 10.0 on the CVSS scoring system.

"Under certain conditions, an authenticated user may be able to cause untrusted code to be executed by the n8n service," n8n said in an advisory released Tuesday. "This could result in full compromise of the affected instance."

Cybersecurity

The maintainers said both self-hosted deployments and n8n Cloud instances are impacted. The issue impacts the following versions -

  • >= 0.123.0
  • < 1.121.3

It has been addressed in version 1.121.3, which was released in November 2025. Security researcher Théo Lelasseux (@theolelasseux) has been credited with discovering and reporting the flaw.

Users are advised to upgrade to this version or later to completely address the vulnerability. If immediate patching is not possible, it's essential that administrators limit exposure by disabling the Git node and limiting access for untrusted users.

The disclosure comes as n8n has addressed a steady stream of critical flaws in the platform (CVE-2025-68613 and CVE-2025-68668, CVSS scores: 9.9) that could lead to code execution under specific conditions.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.


文章来源: https://thehackernews.com/2026/01/n8n-warns-of-cvss-100-rce-vulnerability.html
如有侵权请联系:admin#unsafe.sh