Prototype pollution in n8n - #VU153007
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper control of object prototype attributes in the AI workflow builder's connect-nodes operation when merging workflow connections containing API-submitted node names. A remote user can submit a workflow with a reserved JavaScript property name to cause a denial of service.
The API accepts node names that the editor refuses, and the resulting global object prototype change persists until the instance restarts.