{"id":"CVE-2026-44792","aliases":["GHSA-mhrx-qhrj-673w"],"url":"https://o3.security/vulnerability/CVE-2026-44792","summary":"n8n: Source Control Pull SQL Injection","details":"## Impact\nAn attacker with write access to the git repository connected to an n8n Source Control configuration could commit a malicious Data Table JSON file containing a crafted column name. When an administrator performed a Source Control Pull, n8n imported the file and could lead to SQL injection on the internal PostgreSQL instance.\n\nExploitation requires all of the following conditions:\n- The n8n instance uses PostgreSQL as its database backend.\n- The Source Control feature is enabled and connected to a repository the attacker can write to.\n- An administrator triggers a Source Control Pull.\n\n## Patches\nThe issue has been fixed in n8n version 1.123.43, 2.20.7, and 2.21.1. Users should upgrade to this version or later to remediate the vulnerability.\n\n## Workarounds\nIf upgrading is not immediately possible, administrators should consider the following temporary mitigations:\n- Disable the Source Control feature if it is not actively required.\n- Restrict write access to the connected git repository to fully trusted users only.\n- Avoid pulling from repositories that may have been modified by untrusted parties.\n\nThese workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.","published":"2026-06-23T15:55:30.252Z","modified":"2026-08-12T03:51:15.420192218Z","cvss":null,"epss":{"score":0.00387,"percentile":0.31476,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"1.123.43"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.21.1"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.20.7"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/44xxx/CVE-2026-44792.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-mhrx-qhrj-673w"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-44792"},{"type":"PACKAGE","url":"https://github.com/n8n-io/n8n"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:15.420192218Z"}}