CVE-2026-44790Disclosure(n8n / n8n)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could inject CLI flags on the Git node's Push operation allowing an attacker to read arbitrary files from the n8n server potentially leading to full compromise. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-88

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 11 mentions across 5 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 6 signals
  • Technical details provided in 9 signals
  • Disclosure: 5 classified signals
  • General: 2 classified signals
  • Peaked 3d ago at 3 mentions (2026-05-18); latest day: 1
  • 11 total mentions across 5 days

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline11 mentions / 5d
01223Mentions · 2026-05-14: 1Mentions · 2026-05-18: 3Mentions · 2026-05-19: 3Mentions · 2026-05-20: 3Mentions · 2026-06-10: 1Patch / Workaround · 2026-05-18: 2Patch / Workaround · 2026-05-19: 3Patch / Workaround · 2026-05-20: 1Technical Details · 2026-05-14: 1Technical Details · 2026-05-18: 3Technical Details · 2026-05-19: 3Technical Details · 2026-05-20: 205-1405-1805-1905-2006-10
Signal classification3 categories
Disclosure
545.5%
Patch
436.4%
General
218.2%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-141
Disclosure1
2026-05-183
Disclosure2Patch1
2026-05-193
Patch3
2026-05-203
Disclosure2General1
2026-06-101
General1
Full discourse11 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-44789, CVE-2026-44790 & CVE-2026-44791: 3 new vulnerabilities in n8n, 9.4 rating 🔥 Recently disclosed vulnerabilities in n8n allow an attacker to read arbitrary files from the server, achieve global prototype pollution and bypass the patch for previous vulnerability (CVE-2026-42232). 👉 https://nt.ls/dRB5p

    Post summary

    The text announces three newly disclosed vulnerabilities in n8n (CVE‑2026‑44789, CVE‑2026‑44790, CVE‑2026‑44791) with descriptions of the affected functionalities, but provides no PoC, exploit code, active exploitation evidence, or patch information.

    217055225.7K
    7.6K followersView on X
  • Gray Hats@the_yellow_fall
    Patch

    n8n fixes three critical 9.4 CVSS flaws (CVE-2026-44790/91/89). Authenticated users can break sandboxes for local file read and server-level RCE. Patch now! #n8n #WorkflowAutomation #CyberSecurity #InfoSec #RCE #Vulnerability #DevOps #PrototypePollution https://securityonline.info/n8n-automation-nodes-vulnerabilities-cve-2026-44791-rce/ https://t.co/E2EKNzp94P

    Post summary

    The tweet announces that n8n has released a patch for three critical CVEs (CVE‑2026‑44790/91/89) which allow authenticated users to achieve sandbox escape, file read, and RCE, and urges users to update immediately.

    18039133.9K
    12.5K followersView on X
  • kokumօtօ@__kokumoto
    Disclosure

    n8nにCVSSスコア9.4の重大(Critical)な脆弱性が3件。CVE-2026-44790、CVE-2026-44791、CVE-2026-44789。ワークフローの作成/変更が可能なユーザがインフラ側で任意のコードを実行できる。修正版提供あり。 https://securityonline.info/n8n-automation-nodes-vulnerabilities-cve-2026-44791-rce/

    Post summary

    The post discloses three critical CVEs (CVSS 9.4) in n8n, describes arbitrary code execution via workflow manipulation, and notes that patches are available.

    020721.3K
    7.6K followersView on X
  • GovCERT.CZ@GOVCERT_CZ
    Disclosure

    🚨 Upozorňujeme na sérii zranitelností v platformě n8n, CVE-2026-44789, CVE-2026-44790 a CVE-2026-44791. Byly identifikovány tři kritické chyby v nativních uzlech HTTP Request, Git a XML, které umožňují nízko-privilegovaným autentizovaným útočníkům s oprávněním vytvářet nebo upravovat workflow dosáhnout vzdáleného spuštění kódu (RCE), číst libovolné soubory a v kombinaci zcela kompromitovat server. CVE-2026-44789 zneužívá prototype pollution v HTTP Request Node k dosažení RCE, CVE-2026-44790 umožňuje v Git Node libovolné čtení souborů a CVE-2026-44791 obchází opravy v XML Node a opět vede k RCE; všechny tři zranitelnosti mají CVSS skóre 9,4 a lze je řetězit k úplnému převzetí serveru, což výrazně zvyšuje riziko zejména ve sdílených a multi‑user automatizačních prostředích. Zneužití vyžaduje pouze autentizovaný přístup s nízkými oprávněními, nikoli administrátorská práva. Opravené verze jsou 1.123.43 a novější, 2.20.7 a novější nebo 2.22.1 a novější, a do dokončení nápravy se doporučuje omezit oprávnění k úpravám workflow. 📌 Doporučujeme aktualizovat na nejnovější verzi.

    Post summary

    The text announces three critical CVEs in n8n (CVE-2026-44789/44790/44791), details their technical impact (RCE, file read, prototype pollution, CVSS 9.4), provides patch versions, and advises limiting workflow modification permissions.

    02070681
    4.2K followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    4/5 n8n: five critical vulnerabilities tied to prototype pollution and code execution (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791).

    Post summary

    Five critical prototype-pollution related CVEs affecting n8n have been disclosed, detailing code execution risks.

    100104
    8 followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - n8n Multiple Critical Vulnerabilities (CVE-2026-44791, CVE-2026-44792, CVE-2026-45732, CVE-2026-44789, CVE-2026-44790) Multiple high-severity vulnerabilities were disclosed in n8n, including Prototype Pollution leading to RCE (via XML Node and HTTP Request Node), Arbitrary File Read via Git Node (CLI argument injection), Source Control Pull SQL Injection (PostgreSQL), Cross-user OAuth Credential Takeover, and Credential Exfiltration via SSRF Bypass. These issues can allow remote code execution, unauthorized data access, and credential theft depending on the configuration. 👉Affected: n8n < 1.123.43 | < 2.22.1 | < 2.20.7

    Post summary

    Multiple high‑severity CVEs have been disclosed for n8n, detailing RCE, file read, SQL injection, and credential theft vectors, with no indication of current exploitation or available fixes.

    00020109
    255 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    CVE-2026-44790. 0day Intel: n8n fixes three critical 9.4 CVSS flaws (CVE-2026-44790/91/89). Authenticated us

    Post summary

    The post announces that n8n has patched three critical CVEs, including CVE-2026-44790, providing CVSS scores but no exploit or PoC details.

    1000050
    226 followersView on X
  • Lyrie.ai@lyrie_ai
    Patch

    Vendor v9.4. 0day Intel: n8n fixes three critical 9.4 CVSS flaws (CVE-2026-44790/91/89).

    Post summary

    The post announces that the vendor's v9.4 release includes patches for three critical CVEs, with no mention of POCs, exploits, or active exploitation.

    1000045
    226 followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Patch

    📍 CVE-2026-44790 هالثغره ماتعتبر RCE مباشرة. الثغرة في Git Node Push operation. المهاجم يحقن CLI flags، وهذا يسمح له بقراءة ملفات من سيرفر n8n. GitHub وصفها بأنها Arbitrary File Read وقد تؤدي إلى اختراق كامل السيرفر. الخطر هنا يعتمد على صلاحيات حساب تشغيل n8n. قد يقرأ ملفات مثل: 🔹 ملفات إعدادات n8n والـ .env 🔹 ملفات config 🔹 credentials أو مفاتيح متاحة لحساب الخدمة 🔹 ملفات نظام يستطيع حساب n8n قراءتها مثل etc/shadow ⚠️ تم إغلاق الثغرات في الاصدارات التاليه: 🔹 n8n 1.123.43 🔹 n8n 2.20.7 🔹 n8n 2.22.1

    Post summary

    The tweet announces an arbitrary file‑read vulnerability in n8n’s Git push operation, details its impact and affected files, and confirms that patched releases (1.123.43, 2.20.7, 2.22.1) address the issue.

    00001438
    49.3K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-44790: n8n Git Node Bug - What It Means for Your Business and How to Respond https://hubs.li/Q04kN8PZ0

    Post summary

    The brief headline references CVE‑2026‑44790 but contains no technical, exploitation, or remediation details.

    0000026
    31 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    General

    n8nに重大な脆弱性(CVE-2026-44789・CVE-2026-44790・CVE-2026-44791) https://rocket-boys.co.jp/security-measures-lab/cve-2026-44789-n8n-critical-vulnerabilities/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The provided snippet announces that critical vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) affect n8n, linking to an external page that likely contains further details.

    00000131
    407 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more