Prototype Pollution in n8n Workflow Expressions by n8n.io
CVE-2026-72769

6.1MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72769?

n8n prior to specific versions contains a vulnerability in the VM expression engine that allows authenticated users to manipulate workflow expressions. By exploiting the engine's array-element access, a user can gain access to host built-ins and corrupt their prototypes, leading to unauthorized behavior and instability within the n8n environment. This presents risks for both self-hosted and cloud deployments, compromising service integrity and potentially resulting in denial of service.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
6.1
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.