Fetching from the wire…
Top 5 · 2026-02-23 · source-backed
If you self-host n8n, drop everything and upgrade to v1.121.0. CVE-2026-21858 ("Ni8mare") allows full instance takeover via Content-Type confusion with zero credentials. CVE-2026-25049 bypasses the fix using a single line of destructuring JavaScript. No workarounds exist — patching is the only mitigation. The Hacker News | Geordie Advisory
Each link below shares sources, entities, or timing with this story.
Shared entities / Same source / Shared topic
Both cover Content, CVE, CVSS, JavaScript; cite the same source (The Hacker News); overlapping topics (allow, bypass, confusion, content-type, critical).
Shared entities / Shared topic / What happened next
Both cover Content, CVSS, Ni8mare, Type; overlapping topics (confusion, content-type, cve-2026-21858, cvss); picks up the Content thread on 2026-03-02.
Shared entities / Same source domain / What happened next
Both cover CVE, CVSS, JavaScript, The Hacker News; reported by the same outlet (thehackernews.com); picks up the CVE thread on 2026-03-11.
Shared entities / Same source domain / Shared topic / What happened next
Both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (critical, cvss).
Both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (bypass, cvss).
Shared entities / Same source
Both cover CVE, The Hacker News; cite the same source (The Hacker News, Geordie Advisory).
Shared entities / Same source domain / Shared topic / What happened next / Tension
Both cover CVSS, The Hacker News; reported by the same outlet (thehackernews.com); overlapping topics (bypass, cvss).
Shared entities / Same source domain / What happened next
Both cover CVE, CVSS, The Hacker News; reported by the same outlet (thehackernews.com); picks up the CVE thread on 2026-05-10.