PT-2026-70171 · N8N · N8N
CVE-2026-72769
·
Published
2026-07-22
·
Updated
2026-08-11
CVSS v4.0
6.1
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.67
n8n versions prior to 2.31.5
n8n versions prior to 2.32.1
Description
The VM expression engine contains a prototype pollution issue. An authenticated user with permissions to create or edit workflow expressions can exploit array-element access to obtain a reference to a host built-in. This allows the user to pollute its prototype within the main process, resulting in a sandbox escape—a technique used to bypass the security restrictions of a restricted execution environment—which can lead to a denial of service. Both cloud and self-hosted instances using the VM expression engine are affected.
Recommendations
Update to version 1.123.67 or later.
Update to version 2.31.5 or later.
Update to version 2.32.1 or later.
Exploit
Fix
Prototype Pollution
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N