logo

Critical n8n Vulnerabilities Expose Automation Nodes to Full RCE

ID: c42e2c8f-0070-5cb2-b0e3-e0aaca238b09

STIX ID: report--c42e2c8f-0070-5cb2-b0e3-e0aaca238b09

Feed Name: cybersecurityNews.com

Threat Score
78/100

Date Published: 2026-05-18

Date Updated: 2026-05-19

Author: Abinaya

...
...

n8n disclosed three critical vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) in the HTTP Request, Git, and XML nodes that enable prototype pollution, argument injection, and a patch bypass; when chained, these issues can lead to arbitrary file reads and remote code execution. Affected versions are earlier than 1.123.43, 2.20.7, and 2.22.1; patches are available in 1.123.43, 2.20.7, 2.22.1 and later, and administrators are urged to upgrade immediately or apply temporary mitigations (restrict workflow editing and disable vulnerable nodes via NODES_EXCLUDE).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.