Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.4

CVE-2026-44791: n8n workflow tool could let attackers run code

CVE-2026-44791 · published 1 day ago
Summary

The n8n automation platform had a weakness that could allow a malicious user to execute code on the server running it. This could lead to unauthorized access or data compromise. Update to the latest released version of n8n as soon as possible to apply the fix.

What to do
  • Update GitHub Actions n8n to version 1.123.43.
  • Update GitHub Actions n8n to version 2.22.1.
  • Update GitHub Actions n8n to version 2.20.7.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.3.
  • Update GitHub Actions n8n to version 2.19.3-aikido.3.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.4.
  • Update GitHub Actions n8n to version 2.19.3-aikido.4.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.5.
  • Update GitHub Actions n8n to version 2.19.3-aikido.5.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.6.
  • Update GitHub Actions n8n to version 2.19.3-aikido.6.
  • Update n8n to version 2.19.3-aikido.9.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.9.
  • Update n8n to version 2.19.3-aikido.10.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.10.
  • Update n8n to version 2.19.3-aikido.12.
  • Update rootio @rootio/n8n to version 2.19.3-root.io.12.
Affected software
Ecosystem VendorProductAffected versions
npm GitHub Actions n8n < 1.123.43
>= 2.21.0, < 2.22.1
>= 2.0.0-rc.0, < 2.20.7
Fix: upgrade to 1.123.43
– n8n n8n < 1.123.43
>= 2.0.0, < 2.20.7
>= 2.21.0, < 2.22.1
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Root:npm rootio @rootio/n8n < 2.19.3-root.io.3
< 2.19.3-root.io.4
< 2.19.3-root.io.5
< 2.19.3-root.io.6
< 2.19.3-root.io.9
< 2.19.3-root.io.10
< 2.19.3-root.io.12
Fix: upgrade to 2.19.3-root.io.3
Root:npm GitHub Actions n8n < 2.19.3-aikido.3
< 2.19.3-aikido.4
< 2.19.3-aikido.5
< 2.19.3-aikido.6
Fix: upgrade to 2.19.3-aikido.3
Root:npm – n8n < 2.19.3-aikido.9
< 2.19.3-aikido.10
< 2.19.3-aikido.12
Fix: upgrade to 2.19.3-aikido.9
Original advisory text
CVE-2026-44791 in n8n - Patched by Root
Root has patched CVE-2026-44791 in the n8n package for Root:npm. Multiple fixed versions available.
Fix within
Internet-facing 14 days
Internal At next upgrade
  • Not known to be exploited
  • Needs hands-on effort to exploit
  • Gives an attacker full control
Severity
9.4 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-1321Prototype Pollution
Timeline
Published1 Oct 2026
Updated1 Oct 2026
First seen14 May 2026
Track software like this
Free during beta