PT-2026-40935 · N8N · N8N

Published

2026-05-14

·

Updated

2026-05-21

·

CVE-2026-44791

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.43 n8n versions prior to 2.20.7 n8n versions prior to 2.22.1
Description An authenticated user with permissions to create or modify workflows can bypass a previous prototype pollution patch in the XML node. Prototype pollution occurs when an attacker manipulates the prototype of an object, potentially altering the behavior of the application. When combined with other nodes, this bypass could lead to remote code execution (RCE) on the host system.
Recommendations Update to version 1.123.43 or later. Update to version 2.20.7 or later. Update to version 2.22.1 or later. Limit workflow creation and editing permissions to fully trusted users only. Disable the XML node by adding n8n-nodes-base.xml to the NODES EXCLUDE environment variable.

Fix

Prototype Pollution

Weakness Enumeration

Related Identifiers

CVE-2026-44791
GHSA-WRWR-H859-XH2R

Affected Products

N8N