Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-21858-and-CVE-2025-68613 — Pre-auth n8n exploit chain: arbitrary file read (CVE-2026-21858) to expression-injection RCE (CVE-2025-68613), with Docker lab, PoC scripts, analysis. | Kitploit
Tools/GitHubGitHub/giangdurian/cve-2026-21858-and-cve-2025-68613
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingLearning & EducationLabs & Practice
GitHubgiangdurian/cve-2026-21858-and-cve-2025-68613

CVE-2026-21858-and-CVE-2025-68613

Pre-auth n8n exploit chain: arbitrary file read (CVE-2026-21858) to expression-injection RCE (CVE-2025-68613), with Docker lab, PoC scripts, analysis.

View Repository
71 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

Ni8mare: n8n Pre-Auth RCE (CVE-2026-21858 & CVE-2025-68613) — Vulnerability Lab & PoC Report

Hands-on lab environment (Vulnerable Lab) and a detailed exploitation analysis report of the Ni8mare vulnerability chain on the n8n platform — from Arbitrary File Read (CVE-2026-21858) to Remote Code Execution (CVE-2025-68613), with no authentication required.


Detailed Analysis & Exploitation Report

See the full analysis documentation with step-by-step PoC images in the official report:

View Detailed Exploitation Report (REPORT.md)

(The report includes: n8n architecture analysis, Content-Type Confusion principles, Expression Injection sandbox escape, the exploitation chain from file read to RCE, source code debug traces, root cause analysis, and remediation recommendations.)


Vulnerability Information

AttributeDetails
CVE IDCVE-2026-21858 (File Read) + CVE-2025-68613 (RCE)
NameNi8mare
Vulnerability typeContent-Type Confusion (Arbitrary File Read) + Expression Injection (Sandbox Escape → RCE)
SeverityCritical — CVSS 10.0 + 9.9
Affected productn8n < 1.121.0 (file read) / 0.211.0 – < 1.120.4 (RCE)
Authentication requiredNot required (pre-auth full chain)

Exploitation Chain (Attack Chain)

Content-Type Confusion          Forge Admin JWT          Expression Injection
(CVE-2026-21858)                                        (CVE-2025-68613)

POST application/json    -->   Đọc config + DB    -->   Tạo workflow với
filepath: /etc/passwd          Tính jwt_secret          malicious expression
                               Ký admin token           this.process.mainModule
                                                        .require("child_process")
Arbitrary File Read      -->   Auth Bypass        -->   Remote Code Execution
(CVSS 10.0)                                            (CVSS 9.9)

Lab Startup Guide (Docker)

Requirements

  • Docker & Docker Compose installed on your system.

1. Start the environment

cd ni8mare-lab
docker compose up -d --build

2. Check status

docker compose logs -f

When you see the "Ni8mare Lab -- READY!" banner along with version 1.65.0, the lab is ready. Access n8n at http://localhost:5678/.

  • Admin account: [email protected] / ExploitLab123!
  • Workflow: "Vulnerable Form" (already active)

3. Clean up the environment

docker compose down -v

Repository Structure

├── REPORT.md                    # Báo cáo phân tích kỹ thuật & PoC chi tiết
├── ni8mare-lab/                 # Môi trường Docker lab
│   ├── docker-compose.yml       # Cấu hình Docker n8n 1.65.0
│   ├── Dockerfile               # Custom image với setup script
│   └── init/setup.sh            # Script tạo admin + workflow vulnerable
├── ni8mare_exploit.py           # Exploit script — target Docker Linux (lab)
├── ni8mare_exploit_2.py         # Exploit script — target Windows (n8n build từ source, dùng để debug)
└── img/                         # Hình ảnh minh chứng PoC
    ├── setup-*.png              # Screenshots thiết lập lab
    ├── condition-*.png          # Screenshots điều kiện khai thác
    ├── recon-*.png              # Screenshots reconnaissance
    ├── exploit-*.png            # Screenshots exploitation
    └── debug-*.png              # Screenshots debug source code

References

  • GHSA-v4pr-fm98-w9pg — Advisory CVE-2026-21858 (File Read)
  • GHSA-v98v-ff95-f3cp — Advisory CVE-2025-68613 (RCE)
  • NVD — CVE-2026-21858
  • NVD — CVE-2025-68613
Download Tool