Prototype pollution in n8n - CVE-2026-33696
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to prototype pollution in the GSuiteAdmin node when processing crafted node configuration parameters. A remote user can supply a crafted parameter to write attacker-controlled values onto Object.prototype to execute arbitrary code.
Exploitation requires permission to create or modify workflows.