References https://www.cup.edu.cn/nic/wlaq/926a5deec6654bdba8dfed52533b9c63.htm https://www.twcert.org.tw/newepaper/cp-67-10670-f874f-3.html https://www.cv.ncu.edu.tw/202602101511/ https://cn-sec.com/archives/4199187.html https://www.ithome.com.tw/news/174843 https://www.twcert.org.tw/tw/cp-169-10696-c7fdb-1.html https://cloud.tencent.com/developer/article/2630340 https://www.ithome.com.tw/news/173236 https://cn-sec.com/archives/4869788.html https://www.ithome.com.tw/news/173325 https://www.ithome.com.tw/news/173804 https://www.ithome.com.tw/news/173006 https://www.cyera.com/research/ni8mare-unauthenticated-remote-code-execution-in-n8n-cve-2026-21858 https://research.jfrog.com/post/achieving-remote-code-execution-on-n8n-via-sandbox-escape/ https://nvd.nist.gov/vuln/detail/CVE-2026-33696 https://github.com/SystemVll/CVE-2026-21858 https://censys.com/advisory/cve-2026-21858/ https://www.upwind.io/feed/cve-2026-21858-n8n-unauthenticated-rce https://medium.com/meetcyber/cve-2025-68613-authenticated-remote-code-execution-rce-in-n8n-workflow-automation-platform-b00da2f83c31 https://www.sentinelone.com/vulnerability-database/cve-2026-39974/ https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp
Related VulnerabilitiesN8n N8n 需授权 命令注入漏洞N8n N8n 需授权 表达式注入漏洞PoCCVE-2026-21877: n8n >= 0.123.0 and < 1.121.3 - Remote Code ExecutionN8n N8n 需授权 代码注入漏洞PoCCVE-2026-21858: n8n Webhooks - Remote Code ExecutionPoCCVE-2025-68613: n8n - Remote Code Execution via Expression InjectionN8n N8n 设计缺陷漏洞 可导致沙箱逃逸N8n N8n 外部资源引用不当漏洞PoCn8n-config: N8n - Config