logo

Three Critical 9.4 CVSS Flaws Expose n8n Automation Nodes to Full RCE

ID: 2ac22339-afb2-55d4-a17a-d9bcdec5ee92

STIX ID: report--2ac22339-afb2-55d4-a17a-d9bcdec5ee92

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-18

Date Updated: 2026-05-18

Author: Ddos

...
...

This advisory discloses three critical (CVSS 9.4) vulnerabilities in n8n’s Git, XML, and HTTP Request nodes that can lead to arbitrary file reads, global/prototype pollution, and remote code execution potentially enabling full server takeover; fixes are available in versions 1.123.43, 2.20.7, 2.22.1 and later, and administrators are urged to patch immediately or apply temporary mitigations (revoke workflow editing/creation rights and disable affected nodes via NODES_EXCLUDE).

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.