top of page
perceptive_background_267k.jpg

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compro…

Published:

3 juli 2026 om 22:00:00

Alert date:

4 juli 2026 om 03:05:56

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Enterprise Applications, Identity & Access, Data Breach & Exfiltration

CVE-2025-71380 describes a critical vulnerability in n8n, a workflow automation platform, where the Execute Command node allows authenticated users to run arbitrary commands on the host system. Attackers with valid credentials or compromised accounts can exploit this feature to execute malicious commands. The potential impact includes data exfiltration, service disruption, and complete system compromise. The vulnerability requires authentication, but once access is obtained, exploitation is straightforward. Advisories have been published by both the n8n GitHub security advisory and VulnCheck. Organizations using n8n should review user access controls and consider disabling or restricting the Execute Command node. This vulnerability highlights the risks of powerful automation nodes in workflow platforms when not properly secured.

Technical details

Mitigation steps:

Affected products:

n8n

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page