CVE-2025-71380
n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host
Summary
Affected Packages (2)
| Package | Ecosystem | Affected | Fixed In |
|---|---|---|---|
| n8n-nodes-base | npm | All versions | Range-based data available |
| n8n | npm | All versions | Range-based data available |
Vulnerability Classification
Common Weakness Enumeration (CWE) identifiers for this vulnerability type.
- CWE-78OS Command InjectionMITRE
CVSS Score Breakdown
What the CVSS (Common Vulnerability Scoring System) 8.8 score means for each attack dimension.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
Frequently Asked Questions
- What is CVE-2025-71380?
- n8n: Execute Command Node Allows Authenticated Users to Run Arbitrary Commands on Host This vulnerability has been assigned a severity rating of HIGH (CVSS score: 8.8/10).
- How do I check if my project is affected by CVE-2025-71380?
- CVE-2025-71380 affects n8n-nodes-base and n8n. Use GeekWala's free vulnerability scanner to check your dependencies against CVE-2025-71380 and 200,000+ other known vulnerabilities.
Severity & Exploitability
High exploitability or significant impact. Prioritize remediation within days.
Also Known As
Related CVEs
- CVE-2026-44789CRITICAL
n8n: HTTP Request Node Pagination Prototype Pollution to RCE
- CVE-2026-25052CRITICAL
n8n's Improper File Access Controls Allow Arbitrary File Read by Authenticated Users
- CVE-2026-27498CRITICAL
n8n has Arbitrary Command Execution via File Write and Git Operations
- CVE-2026-72763HIGH
n8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
- CVE-2026-65598HIGH
n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
- CVE-2026-65015HIGH
n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool
- CVE-2025-62726HIGH
n8n Vulnerable to Remote Code Execution via Git Node Pre-Commit Hook
- CVE-2026-65590MEDIUM
n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows
Check if you're affected
Scan your dependencies to see if this vulnerability affects your projects.
Scan Your Dependencies