
🚨High - n8n Multiple Critical Vulnerabilities (CVE-2026-44791, CVE-2026-44792, CVE-2026-45732, CVE-2026-44789, CVE-2026-44790) Multiple high-severity vulnerabilities were disclosed in n8n, including Prototype Pollution leading to RCE (via XML Node and HTTP Request Node), Arbitrary File Read via Git Node (CLI argument injection), Source Control Pull SQL Injection (PostgreSQL), Cross-user OAuth Credential Takeover, and Credential Exfiltration via SSRF Bypass. These issues can allow remote code execution, unauthorized data access, and credential theft depending on the configuration. 👉Affected: n8n < 1.123.43 | < 2.22.1 | < 2.20.7
Post summary
The tweet announces five high‑severity CVEs in n8n with detailed vulnerability types and affected versions, but it does not provide any PoC, exploit code, active exploitation evidence, or patch information.
