Prototype pollution in n8n - #VU153001
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to take over the instance owner's account.
The vulnerability exists due to improper control of object prototype attributes in the MCP workflow-validation interpreter when evaluating caller-supplied code. A remote user can replace a built-in method with one that returns a truthy value to bypass a server-side permission check and take over the instance owner's account.
Accounts protected by MFA are not affected.