CVE-2026-72769: n8n: prototype pollution in VM engine crashes process
UNKNOWNn8n's VM-based workflow expression engine has a prototype pollution flaw (CWE-1321): an authenticated user who can create or edit a workflow expression can abuse array-element access to reach a host built-in, escape the sandbox, and pollute Object.prototype in the main n8n process, crashing it. This isn't a remote, unauthenticated attack — it requires an existing account with workflow-edit rights, which limits the blast radius mostly to insider risk or compromised low-privilege accounts, and correlates with the low EPSS score (0.00253, though ranked in the top 83% percentile of scored CVEs) and CISA's TRACK-only SSVC decision. There's no CISA KEV listing, no public exploit, and no Nuclei template as of publication, so opportunistic mass exploitation is unlikely right now. Because n8n is widely used to orchestrate AI agent workflows, a successful hit takes down not just automation but any AI agent pipelines chained through it, so patch on your normal cycle rather than treating this as an emergency. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1, and in the meantime restrict workflow creation/editing to trusted, need-to-know users.
What is the risk?
Low-to-moderate risk. The vulnerability requires authentication and workflow-edit privileges, so it is not remotely exploitable by an anonymous attacker. No CVSS score has been assigned, EPSS is low (0.00253), CISA SSVC scores it TRACK (lowest urgency tier), and there is no evidence of KEV inclusion, public exploit code, or scanner templates. Impact is limited to denial of service (process crash) rather than data exfiltration or arbitrary remote code execution on the host, which further reduces severity despite the 'sandbox escape' framing. The main residual risk is insider abuse or a compromised low-privilege n8n account being used to repeatedly crash the automation engine.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| n8n | npm | — | No patch |
Do you use n8n? You're affected.
How severe is it?
What should I do?
1 step-
Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately for any instance where non-fully-trusted users can create or edit workflows. As a workaround until patched, restrict workflow creation/edit permissions to trusted administrators only, and review existing user roles for unnecessary editor access. For detection, monitor n8n process logs for unexpected crashes/restarts of the main process, and review recently modified workflow expressions for unusual array-index access patterns targeting global or prototype objects. Track the vendor advisory (GHSA-hx4h-vr3m-45vh) for any updates on exploitability.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-72769?
n8n's VM-based workflow expression engine has a prototype pollution flaw (CWE-1321): an authenticated user who can create or edit a workflow expression can abuse array-element access to reach a host built-in, escape the sandbox, and pollute Object.prototype in the main n8n process, crashing it. This isn't a remote, unauthenticated attack — it requires an existing account with workflow-edit rights, which limits the blast radius mostly to insider risk or compromised low-privilege accounts, and correlates with the low EPSS score (0.00253, though ranked in the top 83% percentile of scored CVEs) and CISA's TRACK-only SSVC decision. There's no CISA KEV listing, no public exploit, and no Nuclei template as of publication, so opportunistic mass exploitation is unlikely right now. Because n8n is widely used to orchestrate AI agent workflows, a successful hit takes down not just automation but any AI agent pipelines chained through it, so patch on your normal cycle rather than treating this as an emergency. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1, and in the meantime restrict workflow creation/editing to trusted, need-to-know users.
Is CVE-2026-72769 actively exploited?
No confirmed active exploitation of CVE-2026-72769 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-72769?
Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately for any instance where non-fully-trusted users can create or edit workflows. As a workaround until patched, restrict workflow creation/edit permissions to trusted administrators only, and review existing user roles for unnecessary editor access. For detection, monitor n8n process logs for unexpected crashes/restarts of the main process, and review recently modified workflow expressions for unusual array-index access patterns targeting global or prototype objects. Track the vendor advisory (GHSA-hx4h-vr3m-45vh) for any updates on exploitability.
What systems are affected by CVE-2026-72769?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow orchestration pipelines, AI automation pipelines.
What is the CVSS score for CVE-2026-72769?
No CVSS score has been assigned yet.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0012 Valid Accounts AML.T0029 Denial of AI Service Compliance Controls Affected
What are the technical details?
Original Advisory
n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.
Exploitation Scenario
A disgruntled contractor or an attacker who has phished/stolen credentials for a low-privilege n8n editor account creates or modifies a workflow expression that uses array-element access to obtain a reference to a JavaScript host built-in inside the VM sandbox. By manipulating that reference, they pollute Object.prototype in the main n8n process rather than the isolated sandbox context, causing the entire n8n server to crash. Because n8n often orchestrates AI agent tool calls and scheduled automations, the outage cascades to every dependent workflow, effectively taking down an organization's AI-driven automation layer until the process is restarted and the malicious workflow is removed.
Weaknesses (CWE)
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
Primary
CWE-1321 Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
- [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
- [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
Source: MITRE CWE corpus.
References
Timeline
Related Vulnerabilities
CVE-2026-33663 10.0 n8n: member role steals plaintext HTTP credentials
Same package: n8n CVE-2026-33660 10.0 TensorFlow: type confusion NPD in tensor conversion
Same package: n8n CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same package: n8n CVE-2026-27577 9.9 n8n: Code Injection enables RCE
Same package: n8n CVE-2026-27494 9.9 n8n: security flaw enables exploitation
Same package: n8n