


Perceptive Security
SOC/SIEM Consultancy

The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compro…
Published:
3 juli 2026 om 22:00:00
Alert date:
4 juli 2026 om 03:05:56
Source:
nvd.nist.gov
Web Technologies, Enterprise Applications, Identity & Access, Data Breach & Exfiltration
CVE-2025-71380 describes a critical vulnerability in n8n, a workflow automation platform, where the Execute Command node allows authenticated users to run arbitrary commands on the host system. Attackers with valid credentials or compromised accounts can exploit this feature to execute malicious commands. The potential impact includes data exfiltration, service disruption, and complete system compromise. The vulnerability requires authentication, but once access is obtained, exploitation is straightforward. Advisories have been published by both the n8n GitHub security advisory and VulnCheck. Organizations using n8n should review user access controls and consider disabling or restricting the Execute Command node. This vulnerability highlights the risks of powerful automation nodes in workflow platforms when not properly secured.
Technical details
Mitigation steps:
Affected products:
n8n
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-71380
https://github.com/n8n-io/n8n/security/advisories/GHSA-365g-vjw2-grx8
https://www.vulncheck.com/advisories/n8n-arbitrary-command-execution-via-execute-command-node
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
