Netlas.io[verified]@Netlas_ioDisclosure
Three new vulnerabilities (CVE‑2026‑44789/44790/44791) have been disclosed in n8n, allowing attackers to read arbitrary files, perform global prototype pollution, and bypass a previous patch for CVE‑2026‑42232.
kokumօtօ[verified]@__kokumotoDisclosure
Three critical CVEs in n8n (CVE-2026-44790, 44791, 44789) allow users who can create or modify workflows to execute arbitrary code; a patch is available.
GovCERT.CZ[verified]@GOVCERT_CZDisclosure
Three critical RCE vulnerabilities in n8n (CVE‑2026‑44789‑44791) have been disclosed, with CVSS scores of 9.4, and users are advised to upgrade to patched versions (1.123.43+, 2.20.7+, or 2.22.1+) or restrict workflow permissions.
Tre B[verified]@trerbbbDisclosure
The post announces GitHub CVE‑2026‑44789 as a remote code execution vulnerability, noting that cloud misconfigurations could widen its impact, but offers no detailed technical or mitigation information.
TodayInCyber[verified]@TodayInCyberIODisclosure
The text announces five critical vulnerabilities in n8n, identifying them as prototype pollution and code execution issues, but provides no further details on PoC, exploits, patches, or active exploitation.
Upwind Security MDR[verified]@UpwindMDRDisclosure
The tweet announces multiple high‑severity vulnerabilities in n8n, detailing the attack vectors (Prototype Pollution, RCE, file read, SQLi, OAuth takeover, SSRF) and the affected versions.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The post announces critical CVEs in n8n and links to an advisory, without providing exploitation details or mitigation information.
Hephaestvs@Vulcanux_Disclosure
The post announces a critical RCE vulnerability (CVE‑2026‑44789) in n8n and notes that updates are available to address it.