Prototype pollution in n8n - CVE-2026-33696
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to prototype pollution in the GSuiteAdmin node when processing crafted node configuration parameters. A remote user can supply a crafted parameter to write attacker-controlled values onto Object.prototype to execute arbitrary code.
Exploitation requires permission to create or modify workflows.