> cat /dev/github | grep security-tools
discovered 11 Aug 2026

CVE-2026-21858

Python ★ 260 via github-topic
→ View on GitHub
The CVE-2026-21858 tool demonstrates a full exploitation chain involving unauthorized arbitrary file read (AFR) and remote code execution (RCE) in the n8n automation platform. By leveraging content-type confusion and expression injection vulnerabilities, it allows an attacker to forge admin tokens and execute commands with critical impact. Key features include automated exploitation via a Python script and specific exploit requirements, such as vulnerable configurations of n8n workflows.