PT-2026-70171 · N8N · N8N

CVE-2026-72769

·

Published

2026-07-22

·

Updated

2026-08-11

CVSS v4.0

6.1

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions prior to 2.31.5 n8n versions prior to 2.32.1
Description The VM expression engine contains a prototype pollution issue. An authenticated user with permissions to create or edit workflow expressions can exploit array-element access to obtain a reference to a host built-in. This allows the user to pollute its prototype within the main process, resulting in a sandbox escape—a technique used to bypass the security restrictions of a restricted execution environment—which can lead to a denial of service. Both cloud and self-hosted instances using the VM expression engine are affected.
Recommendations Update to version 1.123.67 or later. Update to version 2.31.5 or later. Update to version 2.32.1 or later.

Exploit

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72769
GHSA-HX4H-VR3M-45VH

Affected Products

N8N