Critical n8n flaw could enable unauthenticated system takeover

THE BRIEF
CSO Online reports that researchers from data security company Cyera disclosed details of a critical vulnerability in n8n, a platform used by companies to build LLM-powered agents and automated workflows. According to the report, the flaw can let unauthenticated attackers take over local n8n deployments, execute commands on the underlying system, and extract sensitive corporate data accessible through connected workflows. Cyera characterized the potential blast radius as large because n8n may connect organizational Google Drive, OpenAI API keys, Salesforce data, IAM systems, payment processors, customer databases, CI/CD pipelines, and other systems. The n8n developers silently patched the issue in version 1.121.0, released November 18, according to the supplied report. The material provided does not state whether exploitation occurred, how many deployments were affected, or whether any data was accessed. Organizations using local n8n deployments should identify their versions and assess whether the patched release or a later version is installed.
WHY IT MATTERS
This report highlights how a vulnerability in an automation platform may extend beyond that platform when workflows connect business applications, credentials, data stores, and operational systems. The reported ability to execute commands and access workflow-connected information makes version management especially important for organizations running n8n locally. The supplied material does not confirm exploitation or compromise, so the immediate priority is exposure assessment: determine where n8n is deployed, identify installed versions, and verify whether version 1.121.0 or a later release is in use.
WHO SHOULD CARE
Security and infrastructure teams operating local n8n deployments should review exposure. Developers, identity teams, and owners of connected Google Drive, Salesforce, IAM, payment, customer-data, and CI/CD systems should understand whether their workflows depend on the affected platform.
WHAT TO DO NOW
- Inventory local n8n deployments and record the version running on each instance.
- Verify that deployments are running n8n version 1.121.0, released November 18, or a later version.
- Map workflows and integrations connected to Google Drive, OpenAI, Salesforce, IAM, payment, customer database, and CI/CD systems.
- Review available records for unexpected commands or access involving affected n8n deployments, without assuming exploitation occurred.