Prototype pollution in n8n - CVE-2026-44789
Published: May 13, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the HTTP Request node pagination parameter when processing pagination input. A remote user can supply a crafted pagination parameter to execute arbitrary code.
Exploitation requires permission to create or modify workflows.