Fetching from the wire…
Public story · 2026-02-23 · source-backed
The most severe, CVE-2026-21858 ("Ni8mare", CVSS 10.0), allows unauthenticated remote code execution via a Content-Type confusion flaw. CVE-2026-25049 (CVSS 9.4) bypasses the previous fix with a single line of destructuring JavaScript. All self-hosted n8n instances before v1.121.0 are vulnerable. Action required: Upgrade immediately. The attack surface is unauthenticated and internet-reachable.
Source: The Hacker News | SecureLayer7
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source / Shared topic
Both cover Content, CVE, CVSS, JavaScript; cite the same source (The Hacker News); overlapping topics (allow, bypass, confusion, content-type, critical).
Shared entities / Same source domain / Shared topic / What happened next
Both cover Action, CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (action, attack, bypass, cvss).
Shared entities / Shared topic / What happened next
Both cover Content, CVSS, Ni8mare, Type; overlapping topics (code, confusion, content-type, cve-2026-21858, cvss); picks up the Content thread on 2026-03-02.
Shared entities / Same source domain / What happened next
Both cover CVE, CVSS, JavaScript, The Hacker News; reported by the same outlet (thehackernews.com); picks up the CVE thread on 2026-03-11.
Shared entities / Same source domain / Shared topic / What happened next
Both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (code, cvss).
Both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (critical, cvss).
Shared entities / Shared topic / What happened next
Both cover Action, CVE, CVSS; overlapping topics (action, attack, code, critical); picks up the Action thread on 2026-03-05.
Both cover Action, CVE, CVSS; overlapping topics (action, attack, code, cvss); picks up the Action thread on 2026-02-25.