Back to overview

CVE-2025-71380

HIGH
8.8
CVSS 3.1
Description
The Execute Command node in n8n allows authenticated users to execute arbitrary commands on the host system where n8n runs. Attackers with user access or compromised credentials can exploit this node to run malicious commands, potentially leading to data exfiltration, service disruption, or complete system compromise.

Metadata

CVE ID
CVE-2025-71380
State
PUBLISHED
Assigner
VulnCheck
Reserved
2026-06-20 13:11 UTC
Published
2026-07-04 01:23 UTC
Last updated
2026-07-04 01:23 UTC
Primary CWE
CWE-284
Improper Access Control
Vendor / Product
n8n / n8n
Sources
cve.org  ·  NVD

Severity & Metrics

8.8 HIGH CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products (1)
VendorProductPlatformVersions
n8n n8n 0 ≤ 1.114.4
Weakness (CWE)
CWESourceDescription
CWE-284 cna Improper Access Control
CVSS scores (2)
ScoreSeverityVersionSourceVector
8.8 HIGH 3.1 cna CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
8.7 HIGH 4.0 cna CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
References (2)
Back to overview