Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (10 days ago).

← Intel index

This coverage is stale.

Last updated May 21, 2026 (about 3 months ago).

people · May 21, 2026

n8n Patches Five Critical RCE Vulnerabilities with CVSS 9.4 Scores

Share the canonical public link.

Share as image

n8n released security fixes on May 18, 2026 for five critical vulnerabilities CVE-2026-42231, CVE-2026-42232, CVE-2026-44791, CVE-2026-44789, and CVE-2026-44790 each with CVSS score 9.4. Vulnerabilities enable remote code execution via prototype pollution in xml2js library, XML Node, HTTP Request pagination, and CLI flag injection on Git Push for authenticated users with workflow permissions. Patches available in n8n versions 1.123.32, 2.17.4, 2.18.1, 1.123.43, 2.20.7, and 2.22.1. n8n is one of five vendors including Ivanti, Fortinet, SAP, and VMware issuing updates for similar flaws.

Below validation threshold — auto-passed without scoring

Supporting evidence