CVE-2026-44791 Details
Description
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could bypass the patch for CVE-2026-42232 in the XML node. When combined with other nodes, this could lead to RCE on the n8n host. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
A vulnerability exists in n8n, an open-source workflow automation platform, prior to versions 1.123.43, 2.22.1, and 2.20.7. An authenticated user with the ability to create or modify workflows could bypass a security patch in the XML node, originally intended to address a different vulnerability. This bypass, when combined with other nodes, could result in remote code execution on the n8n host.
Users should upgrade to n8n versions 1.123.43, 2.20.7, or 2.22.1. If an immediate upgrade is not possible, consider limiting workflow creation and editing permissions to trusted users and disabling the XML node by adding 'n8n-nodes-base.xml' to the 'NODES_EXCLUDE' environment variable.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/n8n-io/n8n/security/advisories/GHSA-wrwr-h859-xh2r | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1321 | Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| n8n n8n | < 1.123.43 >= 2.0.0, < 2.20.7 >= 2.21.0, < 2.22.1 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 24, 2026 | Initial Analysis | [email protected] |
| Jun 23, 2026 | CVE Modified | CISA-ADP |
| Jun 23, 2026 | New CVE Received | [email protected] |