A critical vulnerability, CVE-2026-21858 (nicknamed “Ni8mare”), affects the n8n workflow automation platform. The flaw stems from improper webhook/form-data request handling in n8n’s file processing path: a file handling function can be invoked without correctly verifying the Content-Type, enabling an unauthenticated remote attacker to manipulate req.body.files or submit specially crafted requests that expose arbitrary files and sensitive data.
This can lead to secret exfiltration, forged administrative access and in chained scenarios, remote code execution and full server compromise. Affected users are recommended to upgrade to the version 1.121.0 and later.
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.
References:

