🚨 Yet another critical (CVSS 10) vulnerability affecting n8n instances tagged as CVE-2026-21877.

If the attack is successful it could result in full compromise of the affected instance.

Vulnerability detection script here:
https://github.com/rxerium/rxerium-templates/blob/main/2026/CVE-2026-21877.yaml

The issue has been resolved in n8n version 1.121.3.

Advisory:
https://github.com/advisories/GHSA-v364-rw7m-3263