CVE-2026-72749: n8n: prototype pollution DoS via Edit Fields node
MEDIUMA prototype pollution flaw in n8n's Edit Fields (Set) node lets any authenticated user name an output field after an inherited JavaScript object path, corrupting a shared global in the main Node.js process. Because that global sits on the request-authentication path, the corruption cascades into every authenticated request failing instance-wide — a full denial of service for all users of that n8n instance, not just the attacker's own workflows. n8n is widely deployed as the orchestration layer for AI agent pipelines, so this can silently halt scheduled agent runs, RAG data-transform steps, and automation triggers until an operator notices and restarts the process. EPSS sits low (0.31%, though ranked in the top 76th percentile of scored CVEs) and CISA's SSVC decision is TRACK — no active exploitation, no public PoC, no Nuclei template — but the bar to trigger it is a single low-privilege authenticated account, not an external attacker. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 now, and in the meantime restrict who can create or edit workflows to trusted users only, since any workflow editor can pull this off with one malformed field name.
What is the risk?
Low technical sophistication but not zero-privilege: exploitation requires only an authenticated n8n account with workflow-edit rights (a role many self-hosted instances grant broadly), and a single crafted field name in the Set node is enough to take down the entire instance for every user. No CVSS score is published and CISA's SSVC lands on TRACK (lowest urgency tier), EPSS is low, there's no CISA KEV listing, no public exploit code, and no scanner template — so opportunistic mass exploitation is unlikely right now. The real risk is availability, not confidentiality/integrity: a disgruntled or compromised low-privilege user, or an automated workflow that happens to echo untrusted input into a Set node field name, can knock out authentication for the whole instance until it's manually restarted.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| n8n | npm | — | No patch |
Do you use n8n? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 immediately, per the GHSA advisory (GHSA-xwx6-jjhv-84p8). Until patched, restrict workflow creation/editing to trusted, vetted users only — this is not exploitable by unauthenticated actors, so tightening role-based access on the n8n instance materially reduces exposure. Audit existing workflows for Set nodes whose field names are dynamically derived from untrusted upstream data (e.g., webhook payloads, LLM output) rather than statically defined, since that's the realistic path for an unintentional or malicious trigger. For detection, monitor for an instance-wide spike in authentication failures with no corresponding credential-related cause, and correlate against recent workflow saves/executions; if the instance becomes unreachable for all authenticated users, a process restart clears the corrupted global as an immediate remediation while the patch is rolled out.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72749?
A prototype pollution flaw in n8n's Edit Fields (Set) node lets any authenticated user name an output field after an inherited JavaScript object path, corrupting a shared global in the main Node.js process. Because that global sits on the request-authentication path, the corruption cascades into every authenticated request failing instance-wide — a full denial of service for all users of that n8n instance, not just the attacker's own workflows. n8n is widely deployed as the orchestration layer for AI agent pipelines, so this can silently halt scheduled agent runs, RAG data-transform steps, and automation triggers until an operator notices and restarts the process. EPSS sits low (0.31%, though ranked in the top 76th percentile of scored CVEs) and CISA's SSVC decision is TRACK — no active exploitation, no public PoC, no Nuclei template — but the bar to trigger it is a single low-privilege authenticated account, not an external attacker. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 now, and in the meantime restrict who can create or edit workflows to trusted users only, since any workflow editor can pull this off with one malformed field name.
Is CVE-2026-72749 actively exploited?
No confirmed active exploitation of CVE-2026-72749 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-72749?
Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 immediately, per the GHSA advisory (GHSA-xwx6-jjhv-84p8). Until patched, restrict workflow creation/editing to trusted, vetted users only — this is not exploitable by unauthenticated actors, so tightening role-based access on the n8n instance materially reduces exposure. Audit existing workflows for Set nodes whose field names are dynamically derived from untrusted upstream data (e.g., webhook payloads, LLM output) rather than statically defined, since that's the realistic path for an unintentional or malicious trigger. For detection, monitor for an instance-wide spike in authentication failures with no corresponding credential-related cause, and correlate against recent workflow saves/executions; if the instance becomes unreachable for all authenticated users, a process restart clears the corrupted global as an immediate remediation while the patch is rolled out.
What systems are affected by CVE-2026-72749?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow automation / orchestration pipelines.
What is the CVSS score for CVE-2026-72749?
CVE-2026-72749 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.57%.
What is the AI security impact?
Affected AI Architectures
Compliance Controls Affected
What are the technical details?
Original Advisory
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output fields via a dot-notation path setter without restricting the field name, allowing an authenticated user to name a field after an inherited built-in method path and corrupt a shared global in the main Node.js process. Because that global is used on the request-authentication path, the instance then fails every authenticated request, causing an instance-wide denial of service for all users until the process is restarted.
Exploitation Scenario
An authenticated n8n user — even one with only workflow-edit privileges, not admin — adds or edits a Set (Edit Fields) node in any workflow and sets an output field name to a dot-notation path targeting the object prototype chain (for example, a path resolving to `__proto__` or `constructor.prototype`) instead of a normal field name. When that workflow runs, the unsanitized path setter walks the prototype chain and overwrites a property on a shared global object in the main Node.js process — a property n8n's authentication middleware also reads. From that point forward, every authenticated HTTP request to the instance, from any user, fails authentication, effectively taking the entire n8n deployment offline, including any AI agent workflows scheduled to run automatically, until an operator restarts the process.
Weaknesses (CWE)
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Primary
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
- [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
- [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H References
Timeline
Related Vulnerabilities
CVE-2026-33663 10.0 n8n: member role steals plaintext HTTP credentials
Same package: n8n CVE-2026-33660 10.0 TensorFlow: type confusion NPD in tensor conversion
Same package: n8n CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same package: n8n CVE-2026-27495 9.9 n8n: Code Injection enables RCE
Same package: n8n CVE-2026-27577 9.9 n8n: Code Injection enables RCE
Same package: n8n