Critical RCE Vulnerability in n8n Workflow Automation Platform (CVE-2026-21877)
A critical remote code execution (RCE) vulnerability, identified as CVE-2026-21877 and rated CVSS 10.0, was disclosed in the open-source workflow automation platform n8n. The flaw allows authenticated users to execute arbitrary code on affected instances, potentially leading to full system compromise. Both self-hosted and n8n Cloud deployments are impacted, specifically versions from 0.123.0 up to but not including 1.121.3. The vulnerability was discovered by security researcher Théo Lelasseux and has been addressed in version 1.121.3, released in November 2025. Administrators are strongly advised to upgrade immediately or, if patching is not possible, to disable the Git node and restrict access for untrusted users to mitigate risk.
The disclosure follows a series of critical vulnerabilities in n8n, highlighting ongoing security challenges for the platform. The Canadian Centre for Cyber Security and other sources have issued advisories urging prompt action to apply the necessary updates. The vulnerability underscores the importance of timely patch management and access control for workflow automation tools, especially those exposed to untrusted users or the internet.

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
3 events from the most recent confirmed update back to the earliest known activity.
Canadian Centre for Cyber Security issues advisory on n8n flaw
On 2026-01-07, the Canadian Centre for Cyber Security published advisory AV26-004 warning about CVE-2026-21877 and urging administrators to review n8n guidance and apply updates. The advisory described the issue as a critical remote code execution vulnerability via arbitrary file write.
n8n publicly discloses CVE-2026-21877 and urges patching
On 2026-01-06, n8n disclosed CVE-2026-21877 as a maximum-severity vulnerability and advised users to upgrade to 1.121.3 or later. The company also recommended mitigations such as disabling the Git node and restricting access for untrusted users if immediate patching was not possible.
n8n releases version 1.121.3 fixing critical RCE flaw
n8n released version 1.121.3 in November 2025 to fix CVE-2026-21877, a critical arbitrary file write issue that can lead to authenticated remote code execution. The flaw affects versions 0.123.0 up to, but not including, 1.121.3 across self-hosted deployments and n8n Cloud.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
2 references tracked. Mallory keeps watching after this page renders.
See the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.

