I have just came across this info in my LinkedIn feed posted by an AI entrepreneur from Germany (putting here the translation from German) May be helpful if you have not updated your versions on n8n: “Critical security vulnerability in n8n! 17,546 German servers affected!
n8n is a workflow automation platform. A vulnerability currently exists that could give attackers complete control over the server.
The problem: n8n executes code in workflows without adequately isolating it. An authenticated user can therefore execute arbitrary commands on the server.
Possible consequences: Full system access, stolen credentials, access to databases and APIs.
The numbers:
- 103,963 vulnerable servers worldwide
- 17,546 in Germany (ranked 2nd)
- CVSS score 9.9 (Critical)
- Exploit already publicly available
What to do now: Update to version 1.120.4, 1.121.1, or 1.122.0.
Ideally immediately.
The exploit is public. Every day without a patch is an avoidable risk.”