CVE-2026-72749: n8n: prototype pollution DoS via Edit Fields node

MEDIUM
Published August 11, 2026
CISO Take

A prototype pollution flaw in n8n's Edit Fields (Set) node lets any authenticated user name an output field after an inherited JavaScript object path, corrupting a shared global in the main Node.js process. Because that global sits on the request-authentication path, the corruption cascades into every authenticated request failing instance-wide — a full denial of service for all users of that n8n instance, not just the attacker's own workflows. n8n is widely deployed as the orchestration layer for AI agent pipelines, so this can silently halt scheduled agent runs, RAG data-transform steps, and automation triggers until an operator notices and restarts the process. EPSS sits low (0.31%, though ranked in the top 76th percentile of scored CVEs) and CISA's SSVC decision is TRACK — no active exploitation, no public PoC, no Nuclei template — but the bar to trigger it is a single low-privilege authenticated account, not an external attacker. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 now, and in the meantime restrict who can create or edit workflows to trusted users only, since any workflow editor can pull this off with one malformed field name.

Sources: NVD GitHub Advisory EPSS VulnCheck

What is the risk?

Low technical sophistication but not zero-privilege: exploitation requires only an authenticated n8n account with workflow-edit rights (a role many self-hosted instances grant broadly), and a single crafted field name in the Set node is enough to take down the entire instance for every user. No CVSS score is published and CISA's SSVC lands on TRACK (lowest urgency tier), EPSS is low, there's no CISA KEV listing, no public exploit code, and no scanner template — so opportunistic mass exploitation is unlikely right now. The real risk is availability, not confidentiality/integrity: a disgruntled or compromised low-privilege user, or an automated workflow that happens to echo untrusted input into a Set node field name, can knock out authentication for the whole instance until it's manually restarted.

How does the attack unfold?

Authenticated access
Attacker obtains or already holds a low-privilege authenticated n8n account with workflow-edit permissions.
AML.T0012
Malicious field crafting
Attacker adds an Edit Fields (Set) node and names an output field using a dot-notation path that resolves to an inherited prototype-chain property instead of a normal field name.
Global corruption
Executing the workflow triggers the unsanitized path setter, overwriting a shared global in the main Node.js process that the authentication middleware also relies on.
Instance-wide denial of service
Every subsequent authenticated request across the entire n8n instance fails, halting all users' access and all scheduled AI agent workflows until the process is manually restarted.

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm — No patch
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
6.5 / 10
EPSS
0.6%
chance of exploitation in 30 days
Higher than 45% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What is the attack surface?

AV AC PR UI S C I A
AV Network
AC Low
PR Low
UI None
S Unchanged
C None
I None
A High

What should I do?

1 step
  1. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 immediately, per the GHSA advisory (GHSA-xwx6-jjhv-84p8). Until patched, restrict workflow creation/editing to trusted, vetted users only — this is not exploitable by unauthenticated actors, so tightening role-based access on the n8n instance materially reduces exposure. Audit existing workflows for Set nodes whose field names are dynamically derived from untrusted upstream data (e.g., webhook payloads, LLM output) rather than statically defined, since that's the realistic path for an unintentional or malicious trigger. For detection, monitor for an instance-wide spike in authentication failures with no corresponding credential-related cause, and correlate against recent workflow saves/executions; if the instance becomes unreachable for all authenticated users, a process restart clears the corrupted global as an immediate remediation while the patch is rolled out.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact partial

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

DoS Agent Framework

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, Robustness and Cybersecurity
ISO 42001
A.6.2.6 - AI system operation and monitoring
OWASP LLM Top 10
LLM10:2025 - Unbounded Consumption

Frequently Asked Questions

What is CVE-2026-72749?

A prototype pollution flaw in n8n's Edit Fields (Set) node lets any authenticated user name an output field after an inherited JavaScript object path, corrupting a shared global in the main Node.js process. Because that global sits on the request-authentication path, the corruption cascades into every authenticated request failing instance-wide — a full denial of service for all users of that n8n instance, not just the attacker's own workflows. n8n is widely deployed as the orchestration layer for AI agent pipelines, so this can silently halt scheduled agent runs, RAG data-transform steps, and automation triggers until an operator notices and restarts the process. EPSS sits low (0.31%, though ranked in the top 76th percentile of scored CVEs) and CISA's SSVC decision is TRACK — no active exploitation, no public PoC, no Nuclei template — but the bar to trigger it is a single low-privilege authenticated account, not an external attacker. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 now, and in the meantime restrict who can create or edit workflows to trusted users only, since any workflow editor can pull this off with one malformed field name.

Is CVE-2026-72749 actively exploited?

No confirmed active exploitation of CVE-2026-72749 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72749?

Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 immediately, per the GHSA advisory (GHSA-xwx6-jjhv-84p8). Until patched, restrict workflow creation/editing to trusted, vetted users only — this is not exploitable by unauthenticated actors, so tightening role-based access on the n8n instance materially reduces exposure. Audit existing workflows for Set nodes whose field names are dynamically derived from untrusted upstream data (e.g., webhook payloads, LLM output) rather than statically defined, since that's the realistic path for an unintentional or malicious trigger. For detection, monitor for an instance-wide spike in authentication failures with no corresponding credential-related cause, and correlate against recent workflow saves/executions; if the instance becomes unreachable for all authenticated users, a process restart clears the corrupted global as an immediate remediation while the patch is rolled out.

What systems are affected by CVE-2026-72749?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow automation / orchestration pipelines.

What is the CVSS score for CVE-2026-72749?

CVE-2026-72749 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.57%.

What is the AI security impact?

Affected AI Architectures

agent frameworksworkflow automation / orchestration pipelines

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: A.6.2.6
OWASP LLM Top 10: LLM10:2025

What are the technical details?

Original Advisory

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global is used on the request-authentication path, the instance then fails every authenticated request, causing an instance-wide denial of service for all users until the process is restarted.

Exploitation Scenario

An authenticated n8n user — even one with only workflow-edit privileges, not admin — adds or edits a Set (Edit Fields) node in any workflow and sets an output field name to a dot-notation path targeting the object prototype chain (for example, a path resolving to `__proto__` or `constructor.prototype`) instead of a normal field name. When that workflow runs, the unsanitized path setter walks the prototype chain and overwrites a property on a shared global object in the main Node.js process — a property n8n's authentication middleware also reads. From that point forward, every authenticated HTTP request to the instance, from any user, fails authentication, effectively taking the entire n8n deployment offline, including any AI agent workflows scheduled to run automatically, until an operator restarts the process.

Weaknesses (CWE)

CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

  • [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
  • [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.

Source: MITRE CWE corpus.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Timeline

Published
August 11, 2026
Last Modified
September 1, 2026
First Seen
August 11, 2026

Related Vulnerabilities