Prototype Pollution Vulnerability in n8n by n8n-io
CVE-2026-72749
7.1HIGH
What is CVE-2026-72749?
n8n versions prior to 1.123.67, 2.31.5, and 2.32.1 contain a prototype pollution vulnerability within the Edit Fields (Set) node. This flaw allows authenticated users to manipulate the output fields via an unrestricted dot-notation path setter. By naming a field after an inherited built-in method path, an attacker can inadvertently corrupt a critical shared global variable within the Node.js main process. This corruption affects the request-authentication pathway and leads to a widespread denial of service, resulting in a failure of all authenticated requests until the affected process is manually restarted.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
