n8n CLI Flag Injection Vulnerability (CVE-2026-44790) — High Severity

The n8n workflow automation platform has a significant security flaw that could allow unauthorized access to sensitive information. This vulnerability, tracked as CVE-2026-44790, is considered high severity and allows an authenticated user to read arbitrary files from the server.

CVE Details

CVE ID: CVE-2026-44790
Product: n8n
Published: June 23, 2026
Severity: HIGH
Status: Analyzed

Affected Products

This vulnerability impacts versions of n8n prior to the following releases:

  • n8n versions before 1.123.43
  • n8n versions before 2.22.1
  • n8n versions before 2.20.7

Current Status

The vulnerability status is “Analyzed,” meaning it has been reviewed and its details confirmed. Patches have been released to address this issue.

Severity Level

This vulnerability is rated as HIGH severity. A high-severity rating indicates that the flaw poses a significant risk, potentially allowing an attacker with authenticated access to compromise the system. In this specific case, an attacker could read sensitive files from the n8n server, which could lead to full system compromise.

Possible Solutions

The good news is that fixes are available. Users are strongly advised to upgrade their n8n installations immediately to a patched version.

  • Apply Patches: Upgrade to n8n version 1.123.43 or later, 2.22.1 or later, or 2.20.7 or later. These versions contain the necessary security fixes.
  • Temporary Workarounds (if immediate upgrade is not possible):
    • Restrict workflow creation and editing permissions strictly to fully trusted users.
    • Temporarily disable the Git node by setting the environment variable NODES_EXCLUDE to include n8n-nodes-base.git. However, these are temporary measures and do not eliminate the risk entirely; a full upgrade is the recommended solution.

References

https://github.com/n8n-io/n8n/security/advisories/GHSA-57g9-58c2-xjg3

Alex Joseph
Alex Joseph

Alex Joseph is a Senior Support Staff professional with deep experience in server management, web hosting technologies, and cybersecurity operations. He works daily with Linux servers, cloud platforms, performance tuning, and security hardening, giving him strong real-world technical knowledge. Along with his support role, he write about security best practices, hosting infrastructure, and software management.