# Using exec node as root

**URL:** <https://discourse.nodered.org/t/using-exec-node-as-root/96737>\
**Category:** General\
**Tags:** exec\
**Created:** [24 April 2025 08:08 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737 "2025-04-24T08:08:38Z")\
**Posts on this page:** 17\
**Page:** 1

<div class="post-metadata">

**Author:** ![lukjasin](https://avatars.discourse-cdn.com/v4/letter/l/90db22/32.png) [@lukjasin](https://discourse.nodered.org/u/lukjasin)\
**Post date:** [24 April 2025 08:08 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/1 "2025-04-24T08:08:38Z")

</div>

I'm new here so first of all hello to everyone.

I have a Victron Cerbo GX with Venus OS and a node-red v3.1.10 instance is running there. Node-red itself works fine, but I have a problem that I lost remote access to the device via ssh. Access is only from the local network, but now I'm far away and unfortunately I don't have the ability to log in from the local network. Node-red is started by the nodered user and I need root access. I know the root password, I have access to the device console etc.

I could modify rc.local to start VPN and restore access. I'm trying to run various commands in the exec node, but everything works for the nodered user, using sudo requires entering the password from the terminal and this can't be done in the node, and ASK\_SUDO and then sudo -A doesn't work in the exec node although I know it works on Venus OS itself (I checked on another device with the same configuration).

Does anyone have an idea how to run commands in the exec node as root?

---

<div class="post-metadata">

**Author:** ![dynamicdave](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/dynamicdave/32/96_2.png) [@dynamicdave](https://discourse.nodered.org/u/dynamicdave)\
**Post date:** [24 April 2025 08:14 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/2 "2025-04-24T08:14:24Z")

</div>

I use this in an exec node on one of my flows to shutdown a Raspberry Pi.

`echo " <insert password here> " | sudo -S shutdown -h now`

 ![thurs_shutdown](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/3X/3/6/368913ad452f04f44b0593421ba411996750b274.png)

**Be cautious** :  
This exposes your password in plaintext, which is insecure and should be avoided in most situations.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2025 08:37 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/3 "2025-04-24T08:37:43Z")

</div>

> [@lukjasin](#):
>
> Does anyone have an idea how to run commands in the exec node as root?

A better idea, avoiding using your password in plain text in the flows file, is to use `sudo your_command` in the exec node, and, in a command window, run `sudo visudo` to allow the node red user to run that command with sudo without having to enter a password.  
So, for example, to allow the use of `sudo shutdown` in an exec node, for the user `nodered`, use `sudo visudo` and add

`nodered ALL=(ALL) NOPASSWD: /sbin/shutdown`

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [24 April 2025 08:51 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/4 "2025-04-24T08:51:08Z")

</div>

A tiny tweek to @dynamicdave's suggestion is to use (eg)

```auto
echo "Password1" | sudo -kS shutdown -h now

```

The -k flag resets the sudo timer, ensuring that sudo does ask for the password every time.

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2025 09:00 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/5 "2025-04-24T09:00:41Z")

</div>

But still the system password is included in plain text in the flow, which is a really bad idea.

---

<div class="post-metadata">

**Author:** ![lukjasin](https://avatars.discourse-cdn.com/v4/letter/l/90db22/32.png) [@lukjasin](https://discourse.nodered.org/u/lukjasin)\
**Post date:** [24 April 2025 09:03 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/6 "2025-04-24T09:03:17Z")

</div>

Thanks for the quick replies.

@dynamicdave and @jbudd  
Passing the password this way does not work on my Node-red instance. I tried a few other methods and they don't work in Node-red either.

@Colin  
Modifying sudoers is possible for root via ssh, but I don't have that access and I want to get it. I'll do it when I get access 😉

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2025 09:05 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/7 "2025-04-24T09:05:37Z")

</div>

> [@lukjasin](#):
>
> Modifying sudoers is possible for root via ssh

Don't modify the file directly, use `visudo`, unless there is really no other option. Otherwise you may end up with a messed up system.

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [24 April 2025 09:14 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/8 "2025-04-24T09:14:52Z")

</div>

> [@Colin](#):
>
> the system password is included in plain text in the flow, which is a really bad idea.

Yes of course it is a really bad idea to expose your password in the flow file.

I think @lukjasin said he does not have ssh access. How can he run visudo?

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [24 April 2025 09:17 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/9 "2025-04-24T09:17:20Z")

</div>

> [@lukjasin](#):
>
> @dynamicdave and @jbudd  
> Passing the password this way does not work on my Node-red instance. I tried a few other methods and they don't work in Node-red either.

Perhaps this is a feature of the Vicron setup, it works for me on a Raspberry Pi.

Can you show us your exec command and the output from exec's stderr?  
Obfuscate your password before posting!

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2025 09:18 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/10 "2025-04-24T09:18:00Z")

</div>

> [@jbudd](#):
>
> I think @lukjasin said he does not have ssh access. How can he run visudo?

He said he is going to get it:

> [@lukjasin](#):
>
> I don't have that access and I want to get it. I'll do it when I get access

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [24 April 2025 09:30 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/11 "2025-04-24T09:30:21Z")

</div>

> [@Colin](#):
>
> He said he is going to get it:
> 
> I don't have that access and I want to get it. I'll do it when I get access

I read that as I'll do it when I get access [by Node-red jiggery-pokery]

I found that I can use exec and a sed command file to edit a root-owned file in a directory I don't have write access to.

```auto
echo 'Password1' | sudo -kS sed -i -f /home/pi/sedfile /var/log/junk

```

---

<div class="post-metadata">

**Author:** ![Colin](https://sea2.discourse-cdn.com/flex026/user_avatar/discourse.nodered.org/colin/32/17040_2.png) [@Colin](https://discourse.nodered.org/u/Colin)\
**Post date:** [24 April 2025 10:13 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/12 "2025-04-24T10:13:23Z")

</div>

It would be dangerous to use something like that to edit `/etc/sudoers` as, if you mess that up, you can end up with an unusable system.

---

<div class="post-metadata">

**Author:** ![lukjasin](https://avatars.discourse-cdn.com/v4/letter/l/90db22/32.png) [@lukjasin](https://discourse.nodered.org/u/lukjasin)\
**Post date:** [24 April 2025 10:25 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/13 "2025-04-24T10:25:15Z")

</div>

I spent quite a bit of time trying different ways to get around the limitations of VenusOS on a Cerbo GX using Node-red - mostly to try and regain access or run privileged commands directly from a flow. And turns out not much luck 😅

Even though echo 'password' | sudo -S ... works fine in a terminal, it doesn’t behave the same in a node-red exec node. Looks like stdin doesn’t get passed to sudo properly in that context.  
VenusOS comes with a super minimal version of sudo, no support for sudo\_askpass (checked with sudo -V, nothing mentioned) and requires tty for password input, which node-red obviously doesn’t have.  
I tried all the usual tricks (echo + sudo, askpass, custom scripts) but it always ends up failing or just silently doing nothing. So yeah, its not really possible to elevate privileges through ode-red alone on this system.

Guess I’ll need to find someone local to connetc into the Cerbo and fix things manually.

And damn… it’s been ages since I last used sed😄

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [25 April 2025 08:43 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/14 "2025-04-25T08:43:56Z")

</div>

@BartButenaers has made an xterm node [https://github.com/bartbutenaers/node-red-contrib-xterm](https://github.com/bartbutenaers/node-red-contrib-xterm) which allows you to run an interactive terminal in the Node-red sidebar.

No idea if it will work on a Victron but on a Raspberry Pi it allows me to do eg `sudo nano /etc/hosts`, prompting for the password.  
I had to change the terminal settings to just 20 rows so I could see what I was editing.

I think a client who had prohibited access via ssh might take a dim view of me subverting it like this, but you may find it useful in an emergency.

---

<div class="post-metadata">

**Author:** ![lukjasin](https://avatars.discourse-cdn.com/v4/letter/l/90db22/32.png) [@lukjasin](https://discourse.nodered.org/u/lukjasin)\
**Post date:** [25 April 2025 10:55 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/15 "2025-04-25T10:55:15Z")

</div>

Hi guys,

I asked around in few more places and one guy on the Victron forum gave me an idea and following that path I was able to solve the problem. This is rather a temporary solution but it seems pretty cool to me. You don't have to store any passwords written in plain text in the nodes, just ssh keys.

As you can see from previous posts, Venus OS on Cerbo GX as a minimalist distribution has a lot of limitations, and not all solutions known from, for example, Raspberry PI will work here. I’ll leave a quick summary here for the community in case someone runs into the same/simillar issue.

The solution was to use Node-Red’s exec node to create a reverse SSH tunnel from the Cerbo GX to a VPS with a public IP.  
Here’s what I did:

1. Generated SSH keys directly from Node-Red (so for user nodered) with exec node:

`ssh-keygen -t rsa -b 2048 -N "" -f /data/home/nodered/.ssh/id_rsa`

1. Copied the public key id\_rsa.pub (just "cat" it with exec node to debug) and added it to the ~/.ssh/authorized\_keys file of a remote VPS user. Make sure permissions are correct:

`chmod 700 ~/.ssh`  
`chmod 600 ~/.ssh/authorized_keys`

1. Created the reverse SSH tunnel from Venus OS to the VPS with exec node:

`ssh -i /data/home/nodered/.ssh/id_rsa -o StrictHostKeyChecking=no -p 22 -N -R 2222:localhost:22 USER@SERVERADDRESS`

1. Connected back to the Venus OS from the VPS:

`ssh -p 2222 root@localhost`

Then, log in with the root password. It can be set remotely in the Remote Console via the VRM Portal:  
Settings → General → Set root password

With this method I was able to fully regain control of the system as root using only Node-Red and a VPS as a tunnel relay over the Internet, no need for local SSH access.  
Hopefully, this helps someone else in a similar situation! 🙌

---

<div class="post-metadata">

**Author:** ![jbudd](https://avatars.discourse-cdn.com/v4/letter/j/5f8ce5/32.png) [@jbudd](https://discourse.nodered.org/u/jbudd)\
**Post date:** [25 April 2025 11:25 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/16 "2025-04-25T11:25:26Z")

</div>

Thanks for explaining your solution. 😁

That's one more tool in the "How to hack Node-red from the internet" box!

Now then, how do I obtain a free VPS to try brute forcing the root password (on my own computers!)?

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/flex026/uploads/nodered/original/1X/d073cd938eafa2e558d7c2cd59003b3ef4963033.png) [@system](https://discourse.nodered.org/u/system)\
**Post date:** [9 May 2025 11:26 UTC](https://discourse.nodered.org/t/using-exec-node-as-root/96737/17 "2025-05-09T11:26:24Z")

</div>

This topic was automatically closed 14 days after the last reply. New replies are no longer allowed.
