people · May 21, 2026
n8n Patches Five Critical RCE Vulnerabilities with CVSS 9.4 Scores
Share the canonical public link.
n8n released security fixes on May 18, 2026 for five critical vulnerabilities CVE-2026-42231, CVE-2026-42232, CVE-2026-44791, CVE-2026-44789, and CVE-2026-44790 each with CVSS score 9.4. Vulnerabilities enable remote code execution via prototype pollution in xml2js library, XML Node, HTTP Request pagination, and CLI flag injection on Git Push for authenticated users with workflow permissions. Patches available in n8n versions 1.123.32, 2.17.4, 2.18.1, 1.123.43, 2.20.7, and 2.22.1. n8n is one of five vendors including Ivanti, Fortinet, SAP, and VMware issuing updates for similar flaws.