References https://cloud.tencent.com/developer/article/2612747 https://github.com/Threekiii/Vulnerability-Wiki/blob/master/docs-base/docs/webapp/n8n-Content-Type-%E6%B7%B7%E6%B7%86%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E8%87%B3-RCE-%E6%BC%8F%E6%B4%9E-CVE-2026-21858.md https://www.venustech.com.cn/new_type/aqldfx/20260113/29095.html https://www.twcert.org.tw/tw/cp-104-10688-91d6d-1.html https://juejin.cn/post/7589166195796803611 https://github.com/n8n-io/n8n/security/advisories/GHSA-v98v-ff95-f3cp https://www.resecurity.com/blog/article/cve-2025-68613-remote-code-execution-via-expression-injection-in-n8n-2 https://thehackernews.com/2026/02/critical-n8n-flaw-cvss-99-enables.html https://github.com/mbanyamer/n8n-Authenticated-Expression-Injection-RCE-CVE-2025-68613 https://cloud.tencent.com/developer/article/2630340
Related VulnerabilitiesN8n N8n 需授权 命令注入漏洞PoCCVE-2026-21877: n8n >= 0.123.0 and < 1.121.3 - Remote Code ExecutionN8n N8n 需授权 代码注入漏洞PoCCVE-2026-21858: n8n Webhooks - Remote Code ExecutionPoCCVE-2025-68613: n8n - Remote Code Execution via Expression InjectionN8n N8n 设计缺陷漏洞 可导致沙箱逃逸N8n N8n 外部资源引用不当漏洞N8n 需授权 外部资源引用不当漏洞 可导致代码执行PoCn8n-config: N8n - Config