Skip to content
n8nGHSA-mhrx-qhrj-673w

n8n Has a Source Control Pull SQL Injection

High9.0CVE-2026-44792 · Published May 14, 2026 · updated Jul 20, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
< 1.123.431.123.43
>= 2.21.0, < 2.21.12.21.1
>= 2.0.0-rc.0, < 2.20.72.20.7
Details and references

## Impact An attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires all of the following conditions: - The n8n instance uses PostgreSQL as its database backend. - The Source Control feature is enabled and connected to a repository the attacker can write to. - An administrator triggers a Source Control Pull. ## Patches The issue has been fixed in n8n version 1.123.43, 2.20.7, and 2.21.1. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Disable the Source Control feature if it is not actively required. - Restrict write access to the connected git repository to fully trusted users only. - Avoid pulling from repositories that may have been modified by untrusted parties. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
CVE-2026-44792

More n8n advisories

All n8n
DateAdvisory
May 14n8n: HTTP Request Node Pagination Prototype Pollution to RCE
CVE-2026-44789Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1
May 14n8n Has an Arbitrary File Read via Git Node
CVE-2026-44790Critical8.8fixed in 1.123.43, 2.20.7, 2.22.1
May 14n8n Has an XML Node Prototype Pollution Patch Bypass
CVE-2026-44791Critical9.9fixed in 1.123.43, 2.20.7, 2.22.1
May 14n8n Has a Cross-user Authorization Bypass in Dynamic Credential OAuth Endpoints
CVE-2026-45732High8.1fixed in 1.123.43, 2.20.7, 2.21.1
May 19n8n: Legacy ExecuteWorkflow Node Bypassed File Path Restrictions
CVE-2026-56352Medium6.4fixed in 2.19.3
May 19n8n: Credential exfiltration via Allowed HTTP Request Domains Bypass
CVE-2026-56348Medium9.1fixed in 2.20.0

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.