n8n Has a Source Control Pull SQL Injection
High9.0CVE-2026-44792 · Published May 14, 2026 · updated Jul 20, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| n8n npm | < 1.123.43 | 1.123.43 |
| >= 2.21.0, < 2.21.1 | 2.21.1 | |
| >= 2.0.0-rc.0, < 2.20.7 | 2.20.7 |
Details and references
## Impact An attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires all of the following conditions: - The n8n instance uses PostgreSQL as its database backend. - The Source Control feature is enabled and connected to a repository the attacker can write to. - An administrator triggers a Source Control Pull. ## Patches The issue has been fixed in n8n version 1.123.43, 2.20.7, and 2.21.1. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Disable the Source Control feature if it is not actively required. - Restrict write access to the connected git repository to fully trusted users only. - Avoid pulling from repositories that may have been modified by untrusted parties. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-89
- Also known as
- CVE-2026-44792
More n8n advisories
All n8n| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 14 | n8n: HTTP Request Node Pagination Prototype Pollution to RCE CVE-2026-44789Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1 | Critical9.9 | 1.123.43, 2.20.7, 2.22.1 |
| May 14 | n8n Has an Arbitrary File Read via Git Node CVE-2026-44790Critical8.8fixed in 1.123.43, 2.20.7, 2.22.1 | Critical8.8 | 1.123.43, 2.20.7, 2.22.1 |
| May 14 | n8n Has an XML Node Prototype Pollution Patch Bypass CVE-2026-44791Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1 | Critical9.9 | 1.123.43, 2.20.7, 2.22.1 |
| May 14 | n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints CVE-2026-45732High8.1fixed in 1.123.43, 2.20.7, 2.21.1 | High8.1 | 1.123.43, 2.20.7, 2.21.1 |
| May 19 | n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions CVE-2026-56352Medium6.4fixed in 2.19.3 | Medium6.4 | 2.19.3 |
| May 19 | n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass CVE-2026-56348Medium9.1fixed in 2.20.0 | Medium9.1 | 2.20.0 |