ctipilot.ch
← Back to Daily brief 2026-05-19
HIGHCVE-2026-42231 +4vulnerability

CVE-2026-42231 / -42232 / -44789 / -44790 / -44791 — n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read

discovered 2026-05-19 05:00 UTCrun 2026-05-19-2505c9182 sourcesmulti-source

n8n published five Critical security advisories on 2026-05-18, two on 2026-05-18 (-42231, -42232) and a follow-on cluster of three (-44789, -44790, -44791) released against later branches (n8n GHSA-q5f4-99jv-pgg5, 2026-05-18; The Hacker News, 2026-05-18). CVE-2026-42231 (CVSS 4.0: 9.4, CWE-1321) is the root cause: a prototype-pollution primitive reachable via crafted XML supplied to the xml2js library used by the n8n webhook handler. Once the global JavaScript object prototype is polluted, the chain pivots into the n8n Git node's SSH operations to achieve RCE on the n8n host by an authenticated user with workflow create / modify permission. CVE-2026-42232 (GHSA-hqr4-h3xv-9m3r, "XML Node Prototype Pollution to RCE") is a companion XML-Node prototype-pollution flaw exercising the same primitive in a second sink. The follow-on advisories: CVE-2026-44789 (GHSA-c8xv-5998-g76h, "HTTP Request Node Pagination Prototype Pollution to RCE"); CVE-2026-44790 (GHSA-57g9-58c2-xjg3, "Arbitrary File Read via Git Node" — a file-read primitive, not the SSH RCE chain); CVE-2026-44791 (GHSA-wrwr-h859-xh2r, "XML Node Prototype Pollution Patch Bypass"). Patched versions split between two branch trains: -42231 and -42232 in n8n 1.123.32 / 2.17.4 / 2.18.1; -44789, -44790 and -44791 in 1.123.43 / 2.20.7 / 2.22.1. No in-the-wild exploitation reported at the time of writing. Inclusion gate: CVSS 9.4 ≥ 9.0 (PD §2 inclusion gate via the CVSS 9.0–10.0 ENISA EUVD threshold).

CVE Summary Table

CVE Product CVSS EPSS KEV Exploited Patch Source
CVE-2026-42231 n8n (xml2js webhook prototype pollution → Git-node SSH RCE chain) 9.4 n/a No No (no public ITW) 1.123.32 / 2.17.4 / 2.18.1 n8n GHSA-q5f4-99jv-pgg5
CVE-2026-42232 n8n (XML Node Prototype Pollution to RCE) 9.4 n/a No No 1.123.32 / 2.17.4 / 2.18.1 n8n GHSA-hqr4-h3xv-9m3r
CVE-2026-44789 n8n (HTTP Request Node Pagination — prototype pollution to RCE) 9.4 n/a No No 1.123.43 / 2.20.7 / 2.22.1 n8n GHSA-c8xv-5998-g76h
CVE-2026-44790 n8n (Arbitrary File Read via Git Node — file-read primitive) 9.4 n/a No No 1.123.43 / 2.20.7 / 2.22.1 n8n GHSA-57g9-58c2-xjg3
CVE-2026-44791 n8n (XML Node Prototype Pollution Patch Bypass) 9.4 n/a No No 1.123.43 / 2.20.7 / 2.22.1 n8n GHSA-wrwr-h859-xh2r

n8n addresses five critical prototype pollution and injection flaws (CVE-2026-42231/42232/44791/44789/44790, all CVSS 9.4)

The Hacker News

An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining the pollution with the Git node's SSH operations, achieve remote code execution on the n8n host

n8n GHSA-q5f4-99jv-pgg5
PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.