n8n hit by CVSS 10.0 chain: unauthenticated file read to full RCE, PoC out

evilsocket · x · 2026-09-17

Automation platform n8n has a public exploit chain, CVE-2026-21858 (codename Ni8mare, CVSS 10.0): unauthenticated arbitrary file read → forge admin JWT → sandbox bypass → RCE, with a working PoC circulating.

Key points:

Original post →

More from coding & agent

coding & agent channel →