n8n hit by CVSS 10.0 chain: unauthenticated file read to full RCE, PoC out
evilsocket · x · 2026-09-17
Automation platform n8n has a public exploit chain, CVE-2026-21858 (codename Ni8mare, CVSS 10.0): unauthenticated arbitrary file read → forge admin JWT → sandbox bypass → RCE, with a working PoC circulating.
Key points:
- Chain: Content-Type confusion enables arbitrary file read → read config + database to forge an admin JWT → expression injection bypasses the sandbox for RCE.
- Affected: ≤1.65.0 (file read) / ≥0.211.0 (RCE); fixed in 1.121.0 and 1.120.4+.
- Disclosed by Dor Attias (Cyera) on 2026-01-07; PoC by Chocapikk, developed AI-automated (patch diff → repro → lab → exploit, 9h post-disclosure).
- The PoC is not universal and requires specific workflow configs; any internet-facing unpatched n8n should be upgraded immediately.
More from coding & agent
- Open-source Helicon app brings Meta's Muse Code CLI to Windows desktop — alexandr_wang · 2026-09-17
- Netlify to livestream a Grok Bot autonomously building and deploying a site — thisiskp_ · 2026-09-17
- OpenJev open-sources Jev-style semantic decisions on a single RTX 3090 with a frozen 4B model — alexcovo_eth · 2026-09-17
- Browser Use CEO on agentic engineering: humans are the bottleneck, he stopped reading code — David Ondrej · 2026-09-17
- Jev: an open-source action-picker that splits agent thinking from clicking — alexcovo_eth · 2026-09-17
- CROA open-sources a deterministic execution layer enforcing trajectory-level constraints on AI agents — CROA_PROJECT · 2026-09-17