Prototype pollution in n8n - CVE-2026-54312
Published: June 16, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improperly controlled modification of object prototype attributes in the Microsoft SQL node when processing a crafted table parameter. A remote user can supply a crafted table parameter to cause a denial of service.
The issue can pollute Object.prototype process-wide for the lifetime of the server process, causing application-wide validation failures until the service is restarted.