{"repo":"Chocapikk/CVE-2026-21858","free":true,"listed":false,"github":"https://github.com/Chocapikk/CVE-2026-21858","clone":"git clone https://github.com/Chocapikk/CVE-2026-21858.git","description":"n8n Ni8mare - Unauthenticated Arbitrary File Read to RCE Chain (CVSS 10.0)","language":"Python","stars":259,"topics":["exploit","n8n","poc","rce","security","vulnerability","cve-2026-21858","ni8mare"],"license":null,"category":"security-tools","readme_excerpt":"CVE-2026-21858 + CVE-2025-68613 - n8n Full Chain Unauthenticated Arbitrary File Read → Admin Token Forge → Sandbox Bypass → RCE --- --- CVE CVE-2026-21858 (AFR) + CVE-2025-68613 (RCE) CVSS 10.0 + 9.9 (Critical) Affected = 0.211.0 (RCE) Fixed 1.121.0 (AFR) / 1.120.4+ (RCE) Disclosed 2026-01-07 11:09 UTC Codename Ni8mare Credit Dor Attias (Cyera) Exploit Chocapikk Process AI-automated: patch diff → repro → lab → exploit ( 9h post-disclosure) Type Proof of Concept - NOT a universal exploit (requires specific workflow config, see Limitations) TL;DR Full unauthenticated RCE chain on n8n: 1. CVE-2026-21858 - Content-Type confusion → Arbitrary File Read 2. Read config + database → forge admin JWT 3. CVE-2025-68613 - Expression injection → sandbox bypass → RCE Detection The exposure is version-based . In terms of exposure, there are vulnerable n8n instances publicly accessible. LeakIX Results: View exposed instances Why This Exploit? This exploit was developed independently from the Cyera write-up (discovered after completion). Key differences: Cyera (Original Research) This Exploit --- --- --- File Read Load into AI knowledge base → query via chat Direct HTTP response Prerequisites Chat workflow + AI integration Any form with file upload RCE Method \"Execute Command\" node (disabled by default) Expression Injection (works on default installs) Automation Manual/conceptual demo Fully automated Python script Both approaches require specific workflow configurations. Cyera needs chat + AI ","default_branch":null,"files":null,"tree":[],"storefront":"/r/Chocapikk","claimed":false,"request_supported":{"post":"https://gitbuyer.com/r/Chocapikk/CVE-2026-21858/request-supported","requests":0},"note":"indexed from public GitHub; nothing is for sale on this page. Clone it from GitHub. Paid listings live at /search."}