A critical remote code execution (RCE) vulnerability has been identified in the n8n workflow automation platform. Affected versions include all prior to 1.123.43, 2.22.1, and 2.20.7. The vulnerability arises from an incomplete patch for CVE-2026-42232 in the XML node, allowing authenticated users with workflow creation or modification permissions to bypass existing protections. When combined with other nodes, this could enable arbitrary code execution on the host. This poses a severe risk to systems utilizing n8n for workflow automation, as attackers could gain full control over the affected host. The CVSS score of 9.9 reflects the critical severity of this issue. Organizations using vulnerable versions of n8n are strongly advised to upgrade to the patched versions immediately to mitigate the risk. No workaround is available aside from applying the latest security updates. This vulnerability underscores the importance of timely patch management for critical infrastructure components.
CRITICAL
CVSS 9.9
CVE-2026-44791
2026-08-22
Critical RCE Vulnerability in n8n Workflow Automation Platform (CVE-2026-44791)
A critical remote code execution vulnerability exists in n8n versions prior to 1.123.43, 2.22.1, and 2.20.7. Authenticated users could exploit this to execute arbitrary code on the host through the XML node.