CVE-2025-71380Patch

LOWCVSS 8.7 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-07-06); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-07-06: 1Mentions · 2026-07-07: 1Patch / Workaround · 2026-07-06: 1Patch / Workaround · 2026-07-07: 1Technical Details · 2026-07-06: 1Technical Details · 2026-07-07: 107-0607-07
Signal classification2 categories
Patch
150.0%
Disclosure
150.0%
Classification over time
DateTotalLabels
2026-07-061
Patch1
2026-07-071
Disclosure1
Full discourse2 posts
  • DFIR Lab@DFIR_Lab
    Disclosure

    🚨 HIGH SEVERITY: CVE-2025-71380 (CVSS 8.8) n8n Execute Command node allows authenticated users to run arbitrary commands on host systems. Risk: data exfiltration, service disruption, full compromise. Restrict node access immediately. #CVE #Vulnerability https://t.co/DiCgCmx1Lc

    Post summary

    The tweet announces a high‑severity vulnerability (CVE‑2025‑71380) in n8n that permits authenticated users to execute arbitrary commands, and urges immediate restriction of node access as a workaround.

    0000042
    66 followersView on X
  • DFIR Lab@DFIR_Lab
    Patch

    🚨 HIGH: CVE-2025-71380 (CVSS 8.8) n8n Execute Command node allows authenticated users to run arbitrary commands on host system. Risk: data exfiltration, service disruption, full compromise. Patch immediately. #CVE #PatchNow https://t.co/26MWSwcdbd

    Post summary

    The post reveals CVE-2025-71380 with a high CVSS 8.8 score, explains that authenticated users can execute arbitrary commands, and strongly urges administrators to apply a patch immediately.

    0000039
    64 followersView on X

Explore more