Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-44789: n8n automation tool could be compromised, patches released

CVE-2026-44789 · published 1 day ago
Summary

The n8n workflow automation software has a security weakness that could let attackers run code or access data. Updated versions of n8n have been released that fix the problem. Apply the latest n8n release as soon as possible to keep your workflows safe.

What to do
  • Update GitHub Actions n8n to version 1.123.43.
  • Update GitHub Actions n8n to version 2.22.1.
  • Update GitHub Actions n8n to version 2.20.7.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.3.
  • Update GitHub Actions n8n to version 2.19.3-aikido.3.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.4.
  • Update GitHub Actions n8n to version 2.19.3-aikido.4.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.5.
  • Update GitHub Actions n8n to version 2.19.3-aikido.5.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.6.
  • Update GitHub Actions n8n to version 2.19.3-aikido.6.
  • Update n8n to version 2.19.3-aikido.9.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.9.
  • Update n8n to version 2.19.3-aikido.10.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.10.
  • Update n8n to version 2.19.3-aikido.11.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.11.
  • Update n8n to version 2.19.3-aikido.12.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.12.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions n8n < 1.123.43
>= 2.21.0, < 2.22.1
>= 2.0.0-rc.0, < 2.20.7
Fix: upgrade to 1.123.43
– n8n n8n < 1.123.43
>= 2.0.0, < 2.20.7
>= 2.21.0, < 2.22.1
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Root:npm rootio @rootio/n8n < 2.19.3-root.io.3
< 2.19.3-root.io.4
< 2.19.3-root.io.5
< 2.19.3-root.io.6
< 2.19.3-root.io.9
< 2.19.3-root.io.10
< 2.19.3-root.io.11
< 2.19.3-root.io.12
Fix: upgrade to 2.19.3-root.io.3
Root:npm GitHub Actions n8n < 2.19.3-aikido.3
< 2.19.3-aikido.4
< 2.19.3-aikido.5
< 2.19.3-aikido.6
Fix: upgrade to 2.19.3-aikido.3
Root:npm – n8n < 2.19.3-aikido.9
< 2.19.3-aikido.10
< 2.19.3-aikido.11
< 2.19.3-aikido.12
Fix: upgrade to 2.19.3-aikido.9
Original advisory text
CVE-2026-44789 in n8n - Patched by Root
Root has patched CVE-2026-44789 in the n8n package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1321Prototype Pollution
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen14 May 2026
Track software like this
Free during beta