---
schema: 1
kind: vulnerability
title: "CVE-2026-42231 / -42232 / -44789 / -44790 / -44791 — n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read"
headline: "CVE-2026-42231 / -42232 / -44789 / -44790 / -44791 — n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE"
summary: "n8n self-hosted automation — five chained critical CVEs (all CVSS 9.4) covering authenticated-to-RCE via xml2js + Git-node SSH plus a separate Git-node arbitrary file read (n8n GHSA-q5f4-99jv-pgg5, 2026-05-18). Patches split across two trains: -42231/-42232 in 1.123.32 / 2.17.4 / 2.18.1; -44789/-44790/-44791 in 1.123.43 / 2.20.7 / 2.22.1. Apply the later train. See deep dive."
discovered_at: "2026-05-19T05:00:05Z"
event_date: 2026-05-18
run_id: 2026-05-19-2505c918
priority: high
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - patch-available
regions:
  - global
  - europe
sectors:
  - technology
  - public-sector
entities: []
cves:
  - id: CVE-2026-42231
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-42232
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-44789
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-44790
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
  - id: CVE-2026-44791
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: post-auth
    status:
      - patch-available
sources:
  - url: "https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5"
    publisher: n8n GHSA-q5f4-99jv-pgg5
    role: primary
  - url: "https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html"
    publisher: The Hacker News
    role: corroborating
closed_sources: []
evidence:
  - quote: "n8n addresses five critical prototype pollution and injection flaws (CVE-2026-42231/42232/44791/44789/44790, all CVSS 9.4)"
    publisher: The Hacker News
  - quote: "An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining the pollution with the Git node's SSH operations, achieve remote code execution on the n8n host"
    publisher: n8n GHSA-q5f4-99jv-pgg5
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-05-19.md
---

n8n published five Critical security advisories on 2026-05-18, two on 2026-05-18 (`-42231`, `-42232`) and a follow-on cluster of three (`-44789`, `-44790`, `-44791`) released against later branches ([n8n GHSA-q5f4-99jv-pgg5, 2026-05-18](https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5); [The Hacker News, 2026-05-18](https://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html)). CVE-2026-42231 (CVSS 4.0: 9.4, CWE-1321) is the root cause: a prototype-pollution primitive reachable via crafted XML supplied to the `xml2js` library used by the n8n webhook handler. Once the global JavaScript object prototype is polluted, the chain pivots into the n8n Git node's SSH operations to achieve RCE on the n8n host by an authenticated user with workflow create / modify permission. CVE-2026-42232 (GHSA-hqr4-h3xv-9m3r, "XML Node Prototype Pollution to RCE") is a companion XML-Node prototype-pollution flaw exercising the same primitive in a second sink. The follow-on advisories: CVE-2026-44789 (GHSA-c8xv-5998-g76h, "HTTP Request Node Pagination Prototype Pollution to RCE"); CVE-2026-44790 (GHSA-57g9-58c2-xjg3, "Arbitrary File Read via Git Node" — a file-read primitive, not the SSH RCE chain); CVE-2026-44791 (GHSA-wrwr-h859-xh2r, "XML Node Prototype Pollution Patch Bypass"). Patched versions split between two branch trains: `-42231` and `-42232` in n8n `1.123.32` / `2.17.4` / `2.18.1`; `-44789`, `-44790` and `-44791` in `1.123.43` / `2.20.7` / `2.22.1`. No in-the-wild exploitation reported at the time of writing. Inclusion gate: CVSS 9.4 ≥ 9.0 (PD §2 inclusion gate via the CVSS 9.0–10.0 ENISA EUVD threshold).


#### CVE Summary Table

| CVE | Product | CVSS | EPSS | KEV | Exploited | Patch | Source |
|---|---|---|---|---|---|---|---|
| CVE-2026-42231 | n8n (xml2js webhook prototype pollution → Git-node SSH RCE chain) | 9.4 | n/a | No | No (no public ITW) | 1.123.32 / 2.17.4 / 2.18.1 | [n8n GHSA-q5f4-99jv-pgg5](https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5) |
| CVE-2026-42232 | n8n (XML Node Prototype Pollution to RCE) | 9.4 | n/a | No | No | 1.123.32 / 2.17.4 / 2.18.1 | [n8n GHSA-hqr4-h3xv-9m3r](https://github.com/n8n-io/n8n/security/advisories/GHSA-hqr4-h3xv-9m3r) |
| CVE-2026-44789 | n8n (HTTP Request Node Pagination — prototype pollution to RCE) | 9.4 | n/a | No | No | 1.123.43 / 2.20.7 / 2.22.1 | [n8n GHSA-c8xv-5998-g76h](https://github.com/n8n-io/n8n/security/advisories/GHSA-c8xv-5998-g76h) |
| CVE-2026-44790 | n8n (Arbitrary File Read via Git Node — file-read primitive) | 9.4 | n/a | No | No | 1.123.43 / 2.20.7 / 2.22.1 | [n8n GHSA-57g9-58c2-xjg3](https://github.com/n8n-io/n8n/security/advisories/GHSA-57g9-58c2-xjg3) |
| CVE-2026-44791 | n8n (XML Node Prototype Pollution Patch Bypass) | 9.4 | n/a | No | No | 1.123.43 / 2.20.7 / 2.22.1 | [n8n GHSA-wrwr-h859-xh2r](https://github.com/n8n-io/n8n/security/advisories/GHSA-wrwr-h859-xh2r) |
