[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"all-banners":3,"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0":44,"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU":51,"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU":57,"vulnerability-29783":64},[4,15,21,27,33,39],{"title":5,"slug":6,"text":7,"link":8,"external":9,"targets":10,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Network Scanner","compliance-pages-launch-network-scanner","Scheduled scans are the spine of every compliance framework. Are you audit-ready?","https:\u002F\u002Fpentest-tools.com\u002Fusage\u002Fcompliance",false,[11],"\u002Fnetwork-vulnerability-scanning\u002Fnetwork-security-scanner-online","Get compliance evidence","secondary","compliance-pages-launch",{"title":16,"slug":17,"text":18,"link":8,"external":9,"targets":19,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Website Scanner","compliance-pages-launch-website-scanner","Authenticated web-app scans show up in SOC 2, NIS2, and CRA Annex I. See why this is crucial for the business.",[20],"\u002Fwebsite-vulnerability-scanning\u002Fwebsite-scanner",{"title":22,"slug":23,"text":24,"link":8,"external":9,"targets":25,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Advanced Pentest Reporting","compliance-pages-launch-reporting","Editable DOCX. Immutable PDF. JSON for the GRC tool. See why these formats are on every auditor's checklist.",[26],"\u002Ffeatures\u002Fpentest-reporting",{"title":28,"slug":29,"text":30,"link":8,"external":9,"targets":31,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Integrations","compliance-pages-launch-integrations","Vanta, Jira, webhooks - they all route back to DORA, NIS2, SOC 2, ISO 27001, CRA. See why this is crucial for the business.",[32],"\u002Ffeatures\u002Fintegrations",{"title":34,"slug":35,"text":36,"link":8,"external":9,"targets":37,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Sniper","compliance-pages-launch-sniper","Five compliance framework pages now reference Sniper as the source of validated exploitability evidence. See them all.",[38],"\u002Fexploit-helpers\u002Fsniper",{"title":40,"slug":14,"text":41,"link":8,"external":9,"targets":42,"cta":12,"variant":13,"campaign_id":14},"Compliance - Page Launch - Homepage","Turn confirmed vulnerabilities into evidence your auditor accepts. Testing requirements for DORA, NIS2, SOC 2, ISO 27001, and CRA.",[43],"\u002F",["Island",45],{"key":46,"params":47,"result":49},"SkipToContent_34xgpJIRRkpiT6ls6jE4NHf7VpvQCQBEwi69exi4oT0",{"props":48},"{}",{"head":50},{},["Island",52],{"key":53,"params":54,"result":55},"FooterNav_JsYsxvLufb1W12aeknKZ89on0MD0bNDTiB5EYxyxmU",{"props":48},{"head":56},{},["Island",58],{"key":59,"params":60,"result":62},"FooterSocial_u16tCafBUeGMoDrdLfTINytP2JB5msc6iB3VDUutAoU",{"props":61},"{\"text-color\":\"gray\"}",{"head":63},{},{"id":65,"detectable_with":66,"vuln_details":72,"vuln_id":93,"name":94,"published":95,"updated":95},29783,{"tool":67,"engine":70},{"id":68,"name":69},1,"Network Scanner",{"id":68,"name":71},"Sniper",{"id":65,"codename":73,"description":74,"severity":75,"risk_description":76,"public_description":77,"public_recommendation":78,"recommendation":79,"references":80,"cvssv3":83,"epss_score":84,"epss_percentile":85,"cve":86,"in_cisa_catalog":9,"date":88,"software_type":89,"vendor":90,"product":90,"ptt_exploit_capabilities":91},"Ni8mare","We found that the target server is running n8n, versions starting with 1.65.0 and below 1.121.0, which is vulnerable to an unauthenticated arbitrary file read that can be chained into remote code execution. n8n selects its request body parser based on the Content-Type header, but the Form Trigger handler consumes the uploaded file's filepath from the request body without first verifying that the request was actually a multipart\u002Fform-data upload. An unauthenticated attacker who reaches an active Form Trigger workflow with a file-upload field can therefore send a JSON body with a forged files object and set filepath to any path on the server, causing n8n to read that file and return it in the workflow response. By reading \u002Fproc\u002Fself\u002Fenviron, the instance encryption key from the .n8n\u002Fconfig file, and the SQLite database, the attacker recovers the owner account's credentials, forges an authenticated admin session cookie, and then abuses the expression-injection sandbox bypass (CVE-2025-68613) in a crafted workflow to execute arbitrary operating system commands.","critical","The risk exists that a remote unauthenticated attacker can fully compromise the server to steal confidential information, install ransomware, or pivot to the internal network.","n8n, versions starting with 1.65.0 and below 1.121.0, is vulnerable to an unauthenticated arbitrary file read that can be escalated to remote code execution. The Form Trigger endpoint reads an uploaded file's path from the request body without confirming the request was a genuine multipart upload, so an attacker can send a JSON body with a forged file object and read any file on the server. Using the leaked encryption key and database, the attacker can forge an administrator session and run arbitrary code on the underlying host.","Update n8n to version 1.121.0 or later.","We recommend updating n8n to version 1.121.0 or later; until the update can be applied, review any workflows that expose Form Trigger nodes to untrusted users and restrict network access to the n8n instance.",[81,82],"https:\u002F\u002Fthehackernews.com\u002F2026\u002F01\u002Fcritical-n8n-vulnerability-cvss-100.html","https:\u002F\u002Fnvd.nist.gov\u002Fvuln\u002Fdetail\u002FCVE-2026-21858",10,0.78447,0.99574,[87],"CVE-2026-21858","2026-01-08T00:00:00Z","Workflow Automation","n8n",[92],"RCE","NETSCAN-SNIPER-CVE-2026-21858","n8n - Remote Code Execution","2026-09-29T00:00:00Z"]