A mid-size logistics company self-hosts n8n to route freight quotes between three carrier APIs and a Slack channel. Nobody on the team ever changed the default admin path, and the webhook endpoint that ingests carrier callbacks sits open on the public internet, because that's how the integration guide said to set it up. In March 2026, Cisco Talos measured a 686% jump year-over-year in phishing emails abusing n8n infrastructure, and two separate critical vulnerabilities, one scored a maximum CVSS 10.0, gave an attacker who found that same open webhook a path to full server takeover. Nothing about the workflow itself was misconfigured for its business purpose. The platform underneath it had two holes big enough to drive a truck through.
What is CVE-2026-21858, the n8n "Ni8mare" vulnerability?
CVE-2026-21858 is an unauthenticated remote code execution bug in n8n's webhook and file-handling logic, caused by content-type confusion. According to Orca Security's analysis, sending a webhook request with a manipulated Content-Type header and body structure overrides n8n's internal request-parsing state, letting an attacker forge uploaded files, read arbitrary local files including credential stores, forge an administrator session, and ultimately execute commands on the host.
It carries a CVSS score of 10.0, the maximum possible, and per Cyera's research, requires no authentication at all: any exposed webhook endpoint is a valid entry point. It affects n8n versions before 1.121.0, which contains the fix.
What is CVE-2025-68613, the expression-injection RCE?
CVE-2025-68613 is a separate, authenticated RCE that lets a logged-in user with workflow-editing rights break out of n8n's expression sandbox. Miggo's write-up explains the root cause: expressions typed into node fields can reach the JavaScript `this` object in a context that isn't properly isolated from the underlying Node.js runtime, which exposes the `process` object and, from there, the ability to run arbitrary code with the privileges of the n8n server.
It carries a CVSS score of 9.9, affects versions from 0.211.0 up to but not including 1.120.4, 1.121.1 and 1.122.0, and CISA added it to its Known Exploited Vulnerabilities catalog in March 2026, meaning it isn't theoretical; it's been used in the wild. The official n8n advisory has the full technical detail.
Why is n8n specifically a growing target for attackers right now?
Because it's trusted infrastructure that most email and network filters don't flag, and it's now the single most reported-on open-source project by security-advisory volume. Cisco Talos's research tracked emails abusing n8n's automation platform from October 2025 through March 2026 and found March 2026 volume roughly 686% higher than January 2025. Attackers use n8n webhook URLs for two things: delivering malware behind a fake CAPTCHA while impersonating trusted cloud services like OneDrive, and fingerprinting recipients with invisible tracking pixels, an `<img>` tag that fires an HTTP request to the attacker's n8n webhook the moment an email is opened.
That abuse doesn't need either CVE to work; it just needs an n8n webhook the attacker controls. But it shows why n8n instances are now actively probed, which means an unpatched, internet-facing instance isn't a hypothetical risk, it's sitting in a scan queue. n8n's own workflow-security node, covered in our guide to securing n8n webhooks with HMAC verification, stops forged payloads but doesn't patch a parser-level flaw like CVE-2026-21858.
Am I actually exposed if I self-host or use n8n Cloud?
n8n Cloud customers were protected by the vendor's own patch rollout and aren't required to act. Self-hosted instances are the real exposure, and the checklist is short:
- **Check your version.** Anything before 1.121.0 is vulnerable to CVE-2026-21858; anything before 1.120.4 / 1.121.1 / 1.122.0 is vulnerable to CVE-2025-68613. Upgrade to the latest stable release, which clears both.
- **Audit webhook exposure.** If your n8n instance's webhook endpoints are reachable from the public internet without a reverse proxy, IP allowlist or auth gate in front of them, that's the exact entry point CVE-2026-21858 needs.
- **Rotate credentials after any exposure window.** If you were running an affected version with public webhooks, treat every credential stored in n8n (API keys, OAuth tokens, database passwords) as potentially read, per IONIX's exploitation writeup, and rotate them.
- **Restrict expression-editing access.** CVE-2025-68613 requires an authenticated user; least-privilege workflow permissions limit who can plant a malicious expression in the first place.
- **No official workaround exists for CVE-2026-21858** short of the version upgrade, per Orca Security's advisory, so patching is not optional, it's the only fix.
Does this mean n8n is unsafe to use for business automation?
No, but it means n8n is infrastructure, and infrastructure needs a patch cadence, not a set-and-forget deployment. The same pattern applies to any self-hosted workflow platform; n8n just carries the most public advisories right now (57, ahead of Claude Code's 22 and AutoGPT's 15, per Talos) because of its popularity, not because it's uniquely fragile. The businesses getting hurt are the ones that stood up an n8n instance eighteen months ago, wired it into production, and never revisited the version number.
The fix isn't abandoning automation, it's treating the automation platform with the same patch discipline you'd apply to a database or an API gateway: pin a version, subscribe to n8n's security advisories, and rebuild the container on every security release rather than waiting for a feature you want.
How AIBOOTSTRAPPER helps
We build and operate n8n-based agents for clients like Leon & Vera's European local studios, where Leon and Vera run 24/7 against real customer channels (see case studies), which means we run patch and exposure audits as a standing part of the build, not an afterthought after a breach. Every automation we ship gets webhook authentication, least-privilege credential scoping and a version-pinning policy from day one.
If you're running n8n in production and aren't sure which version you're on or whether your webhooks are exposed, that's a five-minute check worth doing today. See our AI automation services or book a call if you want it audited properly.
Want this done for you?
Book a free strategy call and we'll show you how to build and market your business with AI.
Sources and further reading
- 1.Orca Security — Critical unauthenticated RCE in n8n (CVE-2026-21858, CVSS 10.0)
- 2.Cyera Research — Ni8mare: Unauthenticated RCE in n8n (CVE-2026-21858)
- 3.Miggo — CVE-2025-68613: n8n Expression Injection RCE
- 4.n8n-io/n8n GitHub Security Advisory GHSA-v98v-ff95-f3cp
- 5.IONIX — CVE-2025-68613: Critical RCE in n8n via Expression Injection
- 6.Cisco Talos Intelligence — The n8n "n8mare": How threat actors are misusing AI workflow automation
