Critical n8n Vulnerabilities Expose Automation Nodes to Full RCE
ID: c42e2c8f-0070-5cb2-b0e3-e0aaca238b09
STIX ID: report--c42e2c8f-0070-5cb2-b0e3-e0aaca238b09
Feed Name: cybersecurityNews.com
n8n disclosed three critical vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) in the HTTP Request, Git, and XML nodes that enable prototype pollution, argument injection, and a patch bypass; when chained, these issues can lead to arbitrary file reads and remote code execution. Affected versions are earlier than 1.123.43, 2.20.7, and 2.22.1; patches are available in 1.123.43, 2.20.7, 2.22.1 and later, and administrators are urged to upgrade immediately or apply temporary mitigations (restrict workflow editing and disable vulnerable nodes via NODES_EXCLUDE).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
