Prototype pollution in n8n - #VU153007

 

Prototype pollution in n8n - #VU153007

Published: September 30, 2026


Vulnerability identifier: #VU153007
CSH Severity: Low
CVSS v4: 7.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-1321
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to cause a denial of service.

The vulnerability exists due to improper control of object prototype attributes in the AI workflow builder's connect-nodes operation when merging workflow connections containing API-submitted node names. A remote user can submit a workflow with a reserved JavaScript property name to cause a denial of service.

The API accepts node names that the editor refuses, and the resulting global object prototype change persists until the instance restarts.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.83, 2.41.4, 2.42.1

External References

Related Security Bulletins