CVE-2026-21858 PUBLISHED CVSS 10 CRITICAL

n8n Vulnerable to Unauthenticated File Access via Improper Webhook Request Handling

EPSS 7.69% · 91.8th percentile

Risk Scores

CVSS v3.1
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
EPSS Score
7.69%
91.8th percentile

Affected Products

VendorProductVersions
n8n-ion8n>= 1.65.0, < 1.121.0
n8nn8n1.65.0
npmn8n1.65.0

Timeline

References

Open in Interactive Console →