n8n versions >= 0.123.0 and < 1.121.3 contain a critical authenticated remote code execution vulnerability via arbitrary file write. An authenticated user can exploit the Git node to overwrite critical files and execute untrusted code on the n8n server, potentially leading to full system compromise. The vulnerability affects both self-hosted and n8n Cloud instances.
id: CVE-2026-21877
info:
name: n8n >= 0.123.0 and < 1.121.3 - Remote Code Execution
author: s4e
...