CVE-2026-21893Disclosure(n8n / n8n)

LOWCVSS 7.2 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. This issue has been patched in version 1.120.3.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 4 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-02-04); latest day: 1
  • 4 total mentions across 2 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-04: 3Mentions · 2026-02-05: 1Patch / Workaround · 2026-02-05: 1Technical Details · 2026-02-04: 3Technical Details · 2026-02-05: 102-0402-05
Signal classification3 categories
Disclosure
250.0%
General
125.0%
Patch
125.0%
Referenced assets5 URLs
Classification over time
DateTotalLabels
2026-02-043
Disclosure2General1
2026-02-051
Patch1
Full discourse4 posts
  • PulsePatch.io@pulsepatchio
    Patch

    n8n is vulnerable to a critical command injection flaw (CVE-2026-21893) in its community package installation. Update to 1.120.3. #n8n #CommandInjection #infosec https://www.pulsepatch.io/posts/cve-2026-21893-n8n-command-injection

    Post summary

    The post alerts users to a critical command injection vulnerability (CVE-2026-21893) in n8n and recommends upgrading to version 1.120.3 to remediate it.

    0000050
    1 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-21893 Command Injection Vulnerability in n8n Workflow Automatio... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-21893 Don't wait vulnerability scanning results: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=2

    Post summary

    The tweet announces CVE-2026-21893 as a command injection flaw in n8n, links to a details page but provides no PoC, exploit, patch, or evidence of active exploitation.

    0000063
    4.0K followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-21893: n8n RCE: Automating Your Own Demise via CVE-2026-21893 A critical OS Command Injection vulnerability in n8n's community package installation logic allows authenticated administrators to execute arbitrary code on the host server. The fl... https://cvereports.com/reports/CVE-2026-21893

    Post summary

    The text announces a critical OS Command Injection vulnerability in n8n's community package installation logic, but provides no PoC, exploit code, active exploitation evidence, or patch details.

    0000058
    27 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-21893: n8n Vulnerable to Command Inject... Admin-to-root privilege escalation in n8n via package installation API - trivial command injection with zero input sani... https://zerodaysignal.com/vulnerability/CVE-2026-21893 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    CVE-2026-21893 is a command injection vulnerability in n8n’s package installation API that enables an admin to elevate privileges to root due to missing input sanitization.

    0000067
    132 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more