Netlas.io[verified]@Netlas_ioDisclosure
The text announces three newly disclosed vulnerabilities in n8n (CVE‑2026‑44789, CVE‑2026‑44790, CVE‑2026‑44791) with descriptions of the affected functionalities, but provides no PoC, exploit code, active exploitation evidence, or patch information.
kokumօtօ[verified]@__kokumotoDisclosure
The post discloses three critical CVEs (CVSS 9.4) in n8n, describes arbitrary code execution via workflow manipulation, and notes that patches are available.
GovCERT.CZ[verified]@GOVCERT_CZDisclosure
The text announces three critical CVEs in n8n (CVE-2026-44789/44790/44791), details their technical impact (RCE, file read, prototype pollution, CVSS 9.4), provides patch versions, and advises limiting workflow modification permissions.
TodayInCyber[verified]@TodayInCyberIODisclosure
Five critical prototype-pollution related CVEs affecting n8n have been disclosed, detailing code execution risks.
Upwind Security MDR[verified]@UpwindMDRDisclosure
Multiple high‑severity CVEs have been disclosed for n8n, detailing RCE, file read, SQL injection, and credential theft vectors, with no indication of current exploitation or available fixes.
Lyrie.ai[verified]@lyrie_aiPatch
The post announces that n8n has patched three critical CVEs, including CVE-2026-44790, providing CVSS scores but no exploit or PoC details.
Lyrie.ai[verified]@lyrie_aiPatch
The post announces that the vendor's v9.4 release includes patches for three critical CVEs, with no mention of POCs, exploits, or active exploitation.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediPatch
The tweet announces an arbitrary file‑read vulnerability in n8n’s Git push operation, details its impact and affected files, and confirms that patched releases (1.123.43, 2.20.7, 2.22.1) address the issue.