CVE-2026-44792

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an administrator triggers a Source Control Pull. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

24 Jun 2026, 13:55

Type Values Removed Values Added
References () https://github.com/n8n-io/n8n/security/advisories/GHSA-mhrx-qhrj-673w - () https://github.com/n8n-io/n8n/security/advisories/GHSA-mhrx-qhrj-673w - Mitigation, Vendor Advisory
CPE cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.0
First Time N8n
N8n n8n

23 Jun 2026, 17:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-06-23 17:16

Updated : 2026-06-24 13:55


NVD link : CVE-2026-44792

Mitre link : CVE-2026-44792

CVE.ORG link : CVE-2026-44792


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-89

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')