NVD Vulnerability Detail
Search Exploit, PoC
CVE-2026-44792
Summary

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an administrator triggers a Source Control Pull. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

Publication Date June 24, 2026, 2:16 a.m.
Registration Date June 27, 2026, 4:14 a.m.
Last Update June 24, 2026, 10:55 p.m.
CVSS3.1 : CRITICAL
スコア 9.0
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
攻撃元区分(AV) ネットワーク
攻撃条件の複雑さ(AC)
攻撃に必要な特権レベル(PR)
利用者の関与(UI)
影響の想定範囲(S) 変更あり
機密性への影響(C)
完全性への影響(I)
可用性への影響(A)
Affected software configurations
Configuration1 or higher or less more than less than
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* 1.123.43
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* 2.0.0 2.20.7
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* 2.21.0 2.22.1
Related information, measures and tools
Common Vulnerabilities List