Netlas.io[verified]@Netlas_ioDisclosure
Three newly disclosed n8n vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) enable arbitrary file reads, global prototype pollution, and patch bypass, but no PoC, exploit code, or active exploitation is referenced.
kokumօtօ[verified]@__kokumotoPatch
Three critical CVEs (CVE-2026-44789/44790/44791) affecting n8n allow users with workflow creation/modification rights to execute arbitrary code; a patch has been released.
GovCERT.CZ[verified]@GOVCERT_CZPatch
Three critical RCE vulnerabilities in n8n with CVSS 9.4 are disclosed, and the advisory recommends updating to patched releases and limiting workflow edit permissions.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediPatch
The post notes a patch bypass for CVE‑2026‑44791, indicating the first patch closed the exploit path but introduced a new issue, and that the vulnerability still allows RCE when privileged workflow accounts are combined with other nodes.
TodayInCyber[verified]@TodayInCyberIODisclosure
The tweet announces the discovery of five critical prototype‑pollution and code‑execution vulnerabilities in n8n (CVE‑2026‑42231, CVE‑2026‑42232, CVE‑2026‑44789, CVE‑2026‑44790, CVE‑2026‑44791) with no exploit or patch details provided.
Upwind Security MDR[verified]@UpwindMDRDisclosure
High‑severity n8n vulnerabilities have been disclosed, including Prototype Pollution leading to remote code execution, arbitrary file read, SQL injection, OAuth credential takeover, and SSRF bypass, impacting all n8n versions below 1.123.43, 2.22.1, and 2.20.7.
IntegSec[verified]@integ_secGeneral
The provided snippet only lists the CVE and a link to additional content, offering no explicit details, exploits, or mitigations.
セキュリティ対策Lab[verified]@securityLab_jpDisclosure
The text announces that n8n has three critical vulnerabilities (CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) and provides a link for further details.