Prototype Pollution Vulnerability in n8n by n8n-io
CVE-2026-72749

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72749?

n8n versions prior to 1.123.67, 2.31.5, and 2.32.1 contain a prototype pollution vulnerability within the Edit Fields (Set) node. This flaw allows authenticated users to manipulate the output fields via an unrestricted dot-notation path setter. By naming a field after an inherited built-in method path, an attacker can inadvertently corrupt a critical shared global variable within the Node.js main process. This corruption affects the request-authentication pathway and leads to a widespread denial of service, resulting in a failure of all authenticated requests until the affected process is manually restarted.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

breakingsystems
.