Rapid7

module

n8n arbitrary file read

Disclosed
N/A
Created
Feb 16, 2026

Description

This module exploits CVE-2026-21858, a critical unauthenticated remote code execution vulnerability in n8n workflow automation platform versions 1.65.0 through 1.120.x. The vulnerability, dubbed "Ni8mare", is a content-type confusion flaw in webhook request handling that allows attackers to achieve arbitrary file read.

Authors

dor attias
msutovsky-r7

Module Options

To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':


msf > use auxiliary/gather/ni8mare_cve_2026_21858
msf auxiliary(ni8mare_cve_2026_21858) > show actions
...actions...
msf auxiliary(ni8mare_cve_2026_21858) > set ACTION < action-name >
msf auxiliary(ni8mare_cve_2026_21858) > show options
...show and set options...
msf auxiliary(ni8mare_cve_2026_21858) > run

Title
Rapid7 Labs

2026 Global Threat Landscape Report

The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.