Intel

AIKIDO-2026-10011

n8n is vulnerable to Remote Code Execution via Path Traversal

Remote Code Execution via Path TraversalCVE-2026-21877

100

Critical Risk

This Affects:

JSn8n
0.123.0 - 1.121.2
Fixed in 1.121.3

TL;DR

Affected versions of n8n are vulnerable to unauthenticated remote code execution.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n is vulnerable to Remote Code Execution via Path Traversal in versions 0.123.0 - 1.121.2.

How to fix this

Upgrade the n8n library to the patch version.