CVE-2026-44792: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in n8n-io n8n
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an administrator triggers a Source Control Pull. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
AI Analysis
Technical Summary
CVE-2026-44792 is an SQL injection vulnerability in n8n prior to versions 1.123.43, 2.20.7, and 2.22.1. An attacker with write access to the git repository used by n8n's Source Control feature can commit a malicious JSON file containing a crafted column name. When an administrator triggers a Source Control Pull, n8n imports this file and executes SQL commands on its internal PostgreSQL database without proper neutralization of special elements, leading to SQL injection. This requires the n8n instance to use PostgreSQL, have Source Control enabled and connected to a repository writable by the attacker, and an administrator to perform the pull. The vulnerability is addressed in the specified fixed versions.
Potential Impact
Successful exploitation can lead to SQL injection on the internal PostgreSQL database used by n8n, potentially allowing an attacker to execute arbitrary SQL commands. This could compromise data integrity, confidentiality, and availability within the affected n8n instance. However, exploitation requires multiple conditions: attacker write access to the connected git repository, use of PostgreSQL as the backend, enabled Source Control feature, and an administrator performing a Source Control Pull.
Mitigation Recommendations
A fix is available in n8n versions 1.123.43, 2.20.7, and 2.22.1. Users should upgrade to these or later versions to remediate this vulnerability. Until upgraded, restrict write access to the git repository connected to n8n Source Control and limit administrative actions that trigger Source Control Pulls. Patch status is confirmed by the vendor through fixed versions; no additional vendor advisory was provided.
CVE-2026-44792: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in n8n-io n8n
Description
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance. Exploitation requires the n8n instance uses PostgreSQL as its database backend, the Source Control feature is enabled and connected to a repository the attacker can write to, and an administrator triggers a Source Control Pull. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
CVSS v4.0
Score 8.9high
Affected software
pkg:github/n8n-io/n8nRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-44792 is an SQL injection vulnerability in n8n prior to versions 1.123.43, 2.20.7, and 2.22.1. An attacker with write access to the git repository used by n8n's Source Control feature can commit a malicious JSON file containing a crafted column name. When an administrator triggers a Source Control Pull, n8n imports this file and executes SQL commands on its internal PostgreSQL database without proper neutralization of special elements, leading to SQL injection. This requires the n8n instance to use PostgreSQL, have Source Control enabled and connected to a repository writable by the attacker, and an administrator to perform the pull. The vulnerability is addressed in the specified fixed versions.
Potential Impact
Successful exploitation can lead to SQL injection on the internal PostgreSQL database used by n8n, potentially allowing an attacker to execute arbitrary SQL commands. This could compromise data integrity, confidentiality, and availability within the affected n8n instance. However, exploitation requires multiple conditions: attacker write access to the connected git repository, use of PostgreSQL as the backend, enabled Source Control feature, and an administrator performing a Source Control Pull.
Mitigation Recommendations
A fix is available in n8n versions 1.123.43, 2.20.7, and 2.22.1. Users should upgrade to these or later versions to remediate this vulnerability. Until upgraded, restrict write access to the git repository connected to n8n Source Control and limit administrative actions that trigger Source Control Pulls. Patch status is confirmed by the vendor through fixed versions; no additional vendor advisory was provided.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2026-05-07T19:20:44.692Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a3ab6d8eed863c81e4f9955
Added to database: 06/23/2026, 16:39:52 UTC
Last enriched: 06/24/2026, 14:39:53 UTC
Last updated: 08/07/2026, 00:41:14 UTC
Views: 95
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.