n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. This issue has been patched in version 1.120.3.
History

Thu, 05 Feb 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
Vendors & Products N8n
N8n n8n

Wed, 04 Feb 2026 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 04 Feb 2026 18:00:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. From version 0.187.0 to before 1.120.3, a command injection vulnerability was identified in n8n’s community package installation functionality. The issue allowed authenticated users with administrative permissions to execute arbitrary system commands on the n8n host under specific conditions. This issue has been patched in version 1.120.3.
Title n8n Vulnerable to Command Injection in Community Package Installation
Weaknesses CWE-20
CWE-78
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2026-02-04T17:36:51.690Z

Updated: 2026-02-04T19:33:50.547Z

Reserved: 2026-01-05T17:24:36.929Z

Link: CVE-2026-21893

cve-icon Vulnrichment

Updated: 2026-02-04T19:33:31.179Z

cve-icon NVD

Status : Received

Published: 2026-02-04T18:16:08.410

Modified: 2026-02-04T18:16:08.410

Link: CVE-2026-21893

cve-icon Redhat

No data.