Impact
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise. The flaw is a classic example of non‑restricted command execution (CWE‑284).
Affected Systems
The flaw affects the n8n workflow automation platform. All installations that expose the Execute Command node to authenticated users are vulnerable. This includes every version of n8n listed by the CNA, though no specific release versions are identified. Therefore, all current releases should be patched or otherwise mitigated.
Risk and Exploitability
The CVSS score of 8.7 marks the vulnerability as high severity. Exploitation requires only authenticated access, with no need for elevated privileges or system compromise beforehand. The EPSS score of < 1% indicates a very low probability of exploitation, though the remote code execution nature keeps the risk high. The vulnerability is not listed in CISA's KEV catalog, so no public exploit is currently known, but the potential damage—including data theft, service disruption, and full system compromise—makes it critical.
OpenCVE Enrichment