CVE-2026-72769: n8n: prototype pollution in VM engine crashes process

UNKNOWN
Published August 11, 2026
CISO Take

n8n's VM-based workflow expression engine has a prototype pollution flaw (CWE-1321): an authenticated user who can create or edit a workflow expression can abuse array-element access to reach a host built-in, escape the sandbox, and pollute Object.prototype in the main n8n process, crashing it. This isn't a remote, unauthenticated attack — it requires an existing account with workflow-edit rights, which limits the blast radius mostly to insider risk or compromised low-privilege accounts, and correlates with the low EPSS score (0.00253, though ranked in the top 83% percentile of scored CVEs) and CISA's TRACK-only SSVC decision. There's no CISA KEV listing, no public exploit, and no Nuclei template as of publication, so opportunistic mass exploitation is unlikely right now. Because n8n is widely used to orchestrate AI agent workflows, a successful hit takes down not just automation but any AI agent pipelines chained through it, so patch on your normal cycle rather than treating this as an emergency. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1, and in the meantime restrict workflow creation/editing to trusted, need-to-know users.

Sources: NVD EPSS GitHub Advisory vulncheck.com ATLAS

What is the risk?

Low-to-moderate risk. The vulnerability requires authentication and workflow-edit privileges, so it is not remotely exploitable by an anonymous attacker. No CVSS score has been assigned, EPSS is low (0.00253), CISA SSVC scores it TRACK (lowest urgency tier), and there is no evidence of KEV inclusion, public exploit code, or scanner templates. Impact is limited to denial of service (process crash) rather than data exfiltration or arbitrary remote code execution on the host, which further reduces severity despite the 'sandbox escape' framing. The main residual risk is insider abuse or a compromised low-privilege n8n account being used to repeatedly crash the automation engine.

How does the attack unfold?

Initial Access
Attacker obtains or already holds an authenticated n8n account with permission to create or edit workflow expressions.
AML.T0012
Sandbox Escape
Attacker crafts a workflow expression using array-element access to obtain a reference to a host built-in object inside the VM expression engine.
Prototype Pollution
Using the host built-in reference, the attacker pollutes Object.prototype in the main n8n process rather than the isolated sandbox.
Impact
The main n8n process crashes, causing denial of service across all workflows and AI agent automations running on that instance.
AML.T0029

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm — No patch
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
N/A
EPSS
0.5%
chance of exploitation in 30 days
Higher than 42% of all CVEs
Exploitation Status
No known exploitation
Sophistication
Moderate

What should I do?

1 step
  1. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately for any instance where non-fully-trusted users can create or edit workflows. As a workaround until patched, restrict workflow creation/edit permissions to trusted administrators only, and review existing user roles for unnecessary editor access. For detection, monitor n8n process logs for unexpected crashes/restarts of the main process, and review recently modified workflow expressions for unusual array-index access patterns targeting global or prototype objects. Track the vendor advisory (GHSA-hx4h-vr3m-45vh) for any updates on exploitability.

What does CISA's SSVC say?

Decision Track
Exploitation none
Automatable No
Technical Impact total

Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
ISO 42001
Clause 8.2 - Operational planning and control
NIST AI RMF
MEASURE 2.7 - AI system security and resilience evaluation
OWASP LLM Top 10
LLM04 - Model Denial of Service

Frequently Asked Questions

What is CVE-2026-72769?

n8n's VM-based workflow expression engine has a prototype pollution flaw (CWE-1321): an authenticated user who can create or edit a workflow expression can abuse array-element access to reach a host built-in, escape the sandbox, and pollute Object.prototype in the main n8n process, crashing it. This isn't a remote, unauthenticated attack — it requires an existing account with workflow-edit rights, which limits the blast radius mostly to insider risk or compromised low-privilege accounts, and correlates with the low EPSS score (0.00253, though ranked in the top 83% percentile of scored CVEs) and CISA's TRACK-only SSVC decision. There's no CISA KEV listing, no public exploit, and no Nuclei template as of publication, so opportunistic mass exploitation is unlikely right now. Because n8n is widely used to orchestrate AI agent workflows, a successful hit takes down not just automation but any AI agent pipelines chained through it, so patch on your normal cycle rather than treating this as an emergency. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1, and in the meantime restrict workflow creation/editing to trusted, need-to-know users.

Is CVE-2026-72769 actively exploited?

No confirmed active exploitation of CVE-2026-72769 has been reported, but organizations should still patch proactively.

How to fix CVE-2026-72769?

Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately for any instance where non-fully-trusted users can create or edit workflows. As a workaround until patched, restrict workflow creation/edit permissions to trusted administrators only, and review existing user roles for unnecessary editor access. For detection, monitor n8n process logs for unexpected crashes/restarts of the main process, and review recently modified workflow expressions for unusual array-index access patterns targeting global or prototype objects. Track the vendor advisory (GHSA-hx4h-vr3m-45vh) for any updates on exploitability.

What systems are affected by CVE-2026-72769?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow orchestration pipelines, AI automation pipelines.

What is the CVSS score for CVE-2026-72769?

No CVSS score has been assigned yet.

What is the AI security impact?

Affected AI Architectures

agent frameworksworkflow orchestration pipelinesAI automation pipelines

MITRE ATLAS Techniques

AML.T0012 Valid Accounts
AML.T0029 Denial of AI Service

Compliance Controls Affected

EU AI Act: Article 15
ISO 42001: Clause 8.2
NIST AI RMF: MEASURE 2.7
OWASP LLM Top 10: LLM04

What are the technical details?

Original Advisory

n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the VM expression engine. An authenticated user able to create or edit a workflow expression can abuse the engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process (a sandbox escape), leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected.

Exploitation Scenario

A disgruntled contractor or an attacker who has phished/stolen credentials for a low-privilege n8n editor account creates or modifies a workflow expression that uses array-element access to obtain a reference to a JavaScript host built-in inside the VM sandbox. By manipulating that reference, they pollute Object.prototype in the main n8n process rather than the isolated sandbox context, causing the entire n8n server to crash. Because n8n often orchestrates AI agent tool calls and scheduled automations, the outage cascades to every dependent workflow, effectively taking down an organization's AI-driven automation layer until the process is restarted and the malicious workflow is removed.

Weaknesses (CWE)

CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

  • [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
  • [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.

Source: MITRE CWE corpus.

Timeline

Published
August 11, 2026
Last Modified
September 9, 2026
First Seen
August 11, 2026

Related Vulnerabilities