Skip to main content
New Year’s Sale — Build a balanced news diet with 40% off Vantage
Published loading...Updated

Max severity Ni8mare flaw lets hackers hijack n8n servers

The Ni8mare vulnerability (CVE-2026-21858) scores 10/10 severity and affects over 100,000 servers, enabling remote code execution without authentication.

  • On November 9, 2025, Cyera researchers reported Ni8mare , a maximum-severity flaw allowing remote attackers control over about 100,000 n8n workflow automation platform servers.
  • N8n's webhook parser uses separate handlers based on content-type, enabling attackers to bypass the upload parser by sending application/json and control req.body.files and the filepath parameter, Cyera said.
  • By controlling file metadata, an attacker can copy arbitrary local files on the underlying server, read secrets and sensitive data stored in workflows, and achieve full remote-code execution with no workaround.
  • Users are advised to update to n8n version 1.121.1 or later, as n8n developers say the patch effectively addresses the vulnerability, after Cyera published proof-of-concept on Wednesday.
  • Widespread adoption of n8n matters because over 50,000 weekly npm downloads and more than 100 million Docker pulls increase risk to API keys, OAuth tokens, and enterprise automation infrastructure, Cyera said.
Insights by Ground AI

10 Articles

Think freely.Subscribe and get full access to Ground NewsSubscriptions start at $9.99/yearSubscribe

Bias Distribution

  • 100% of the sources are Center
100% Center

Factuality Info Icon

To view factuality data please Upgrade to Premium

Ownership

Info Icon

To view ownership data please Upgrade to Vantage

The Hacker News broke the news in on Wednesday, January 7, 2026.
Too Big Arrow Icon
Sources are mostly out of (0)

Similar News Topics

News
Feed Dots Icon
For You
Search Icon
Search
Blindspot LogoBlindspotLocal