Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacyΒ© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-21858-n8n-FullChain β€” πŸ›‘οΈ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain). | Kitploit
Tools/GitHubGitHub/zerodayevil/cve-2026-21858-n8n-fullchain
Vulnerability ScannersVulnerability AnalysisExploitationWeb Application ExploitationPost-ExploitationWeb SecurityPenetration TestingRed TeamingPayload Development
AI Security
GitHubzerodayevil/cve-2026-21858-n8n-fullchain

CVE-2026-21858-n8n-FullChain

πŸ›‘οΈ Official AI Security Tool module for CVE-2026-21858 + CVE-2025-68613 (n8n "Ni8mare" Unauthenticated Arbitrary File Read & Expression Injection RCE Full Chain).

View Repository
8812221 days agoNot yet reviewed

Most Popular

View all β†’

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools β†’
Share

πŸ›‘οΈ AI Security Tool Module
n8n Full Chain (CVE-2026-21858 + CVE-2025-68613) β€” "Ni8mare"

Official Security Audit Module for AI Security Tool Ecosystem


Latest Release Build Status Donations Telegram Channel License

🌐 Web Demo β€’ πŸ“š Project Website β€’ πŸ’¬ Community Chat

Website Navigation: Home β€’ Updates β€’ Downloads β€’ Modules

AI Security Tool Banner


🧠 Conceptual Overview

This module provides diagnostic tools and a complete exploitation chain for n8n workflow automation instances, dubbed Ni8mare.

The attack chain combines an unauthenticated Arbitrary File Read (CVE-2026-21858) caused by Content-Type confusion with an authenticated Expression Injection Sandbox Bypass (CVE-2025-68613). By sending a manipulated Content-Type: application/json request to an exposed file upload form, an attacker controls the filepath argument to read internal system files (/proc/self/environ, configuration, and SQLite DB). The retrieved encryptionKey and password hash allow offline forgery of an administrator JWT cookie. Once authenticated, expression injection via this.process.mainModule.require escapes the JavaScript sandbox to execute arbitrary system commands.

🎯 Core Impact Philosophy

"From file read to full system takeover in three steps."
While the file read requires an active form workflow with binary output, expression injection works reliably on default n8n installations without requiring special nodes or explicit system permissions enabled.

πŸ“Š Vulnerability Specifications

Specification Assigned Value Notes
CVE Identifiers CVE-2026-21858 + CVE-2025-68613 Full Chain: Unauthenticated File Read to RCE
Severity Rating Critical (CVSS v3.1: 10.0 + 9.9) Unauthenticated RCE chain
Vulnerability Types CWE-200 / CWE-94 Content-Type Confusion / Code Injection
Affected Component n8n Workflow Automation Engine Versions <= 1.65.0 (AFR) / >= 0.211.0 (RCE)
Patched Versions 1.121.0 (AFR) / 1.120.4+ (RCE) Official vendor patches released
Privileges Required None Unauthenticated initial access via public form

πŸ•Έ Attack Scenario & Architecture

graph TD
    A[Unauthenticated Attacker] -->|1. Content-Type Confusion| B[Vulnerable Form Endpoint]
    B -->|2. Arbitrary File Read| C[Extract /proc/self/environ & database.sqlite]
    C -->|3. Derive Secret & Hash| D[Forge Admin JWT Cookie]
    D -->|4. Authenticate as Admin| E[n8n Workflow Engine]
    E -->|5. Expression Injection Payload| F[Sandbox Escape via mainModule.require]
    F -->|6. Execute Command| G[Full Remote Code Execution]
  

πŸ’» Expression Injection Payload

={{ (function() {
  var require = this.process.mainModule.require;
  var execSync = require("child_process").execSync;
  return execSync("id").toString();
})() }}

πŸ›‘ Mitigation Checklist

  • 🟒 Upgrade Immediately: Update n8n instances to version 1.121.0 or higher.
  • 🟒 Restrict Workflow Triggers: Disable public unauthenticated form workflows or enforce strict file validation.
  • 🟑 Configure Execution Restrictions: Set N8N_ENFORCE_SETTINGS_FILE_PERMISSIONS=true and restrict process capabilities in Docker containers.

πŸ’» How to Run this Module

⚠️ IMPORTANT: This module is built specifically for safe execution and diagnostics within the AI Security Tool ecosystem. Always use verified modules sourced from official repositories.

1️⃣ Install AI Security Tool

To execute the monitoring and diagnostic scripts, ensure the AI Security Tool core engine is installed:

Download Tool