CVE-2026-72769High· 8.1▾ Twilightn8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a …
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44.6 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Sep 9.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.3%
Last analysed / modified upstream
— → 8.1
none → high
0.3% → 0.3%
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.
n8n < 1.123.67n8n >= 2.0.0, < 2.31.5n8n = 2.32.0Upgrade past the affected range:
n8n 2.31.5Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-hx4h-vr3m-45vhMediumn8n: Prototype Pollution via VM Expression Engine Sandbox Escape Leads to Denial of Service
CVE-2026-86078Medium· 6.5n8n is an open source workflow automation platform
GHSA-xwx6-jjhv-84p8Highn8n: Prototype Pollution via Dot-Notation Field Names Leads To Instance-Wide Denial of Service
CVE-2026-59206Highn8n: Prototype Pollution via Workflow Credentials Leads to Unauthenticated User and Project Enumeration
CVE-2026-54306Medium· 5.4n8n: Prototype Pollution enables confused-deputy execution via public webhooks
CVE-2026-54312High· 8.5n8n: Microsoft SQL Node Prototype Pollution