Workflow Automation Platform Vulnerability in n8n
CVE-2026-44790
9.4CRITICAL
What is CVE-2026-44790?
An issue has been identified in n8n, an open-source workflow automation platform, where prior versions (before 1.123.43, 2.22.1, and 2.20.7) permitted authenticated users to introduce CLI flags in the Git node's Push operation. This exploitation could enable attackers to read arbitrary files from the n8n server, posing a significant security risk and potentially compromising the entire system. Users are strongly advised to update to the latest versions to safeguard against this vulnerability.
Affected Version(s)
n8n < 1.123.43 < 1.123.43
n8n >= 2.0.0-rc.0, < 2.20.7 < 2.0.0-rc.0, 2.20.7
n8n >= 2.21.0, < 2.21.1 < 2.21.0, 2.21.1
