GHSA-hx4h-vr3m-45vh: n8n: prototype pollution in expression engine causes DoS
GHSA-hx4h-vr3m-45vh MEDIUMn8n's VM-based workflow expression engine lets an authenticated user reach a reference to a host JavaScript built-in through array-index access and pollute its prototype, crashing the shared Node.js process that runs every workflow on the instance. Because n8n runs as an AI-agent orchestration layer with 16 downstream dependents and a package risk score of 69/100, a single malicious or compromised workflow editor can take down automation and AI-agent pipelines for the entire tenant, not just their own workflow. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit/Nuclei template yet, so this reads as a low-noise disclosure rather than an actively exploited bug, but the underlying primitive (prototype pollution reachable from user-controlled expressions) is well understood and easy to weaponize once a PoC surfaces. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately; if you can't patch now, restrict workflow-creation/edit rights to fully trusted users and disable the VM expression engine where an alternative exists, since both are only partial mitigations.
What is the risk?
Rated medium severity by the advisory with no published CVSS vector. Exploitation requires an authenticated account with workflow create/edit rights, which limits the exposure surface compared to unauthenticated bugs but is a low bar in typical multi-user or multi-team n8n deployments where several people routinely get editor access. No active-exploitation signals exist: not in CISA KEV, no EPSS score, no public exploit code, no Nuclei template, so near-term opportunistic risk is low. The package's broader risk posture is elevated (166 other CVEs on record, OpenSSF Scorecard 6.6/10), which argues for a generally tighter patch cadence on n8n regardless of this specific issue.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| n8n | npm | < 1.123.67 | 1.123.67 |
Do you use n8n? You're affected.
How severe is it?
What should I do?
1 step-
Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 (or later) as soon as possible — this is the only full remediation. If upgrading isn't immediately feasible, restrict workflow creation/editing to fully trusted users only and disable the VM expression engine if your deployment supports a non-VM alternative; treat both as short-term, partial mitigations. For detection, monitor for unexpected n8n process crashes or restarts correlated with workflow save/edit events, and audit recent expression changes by non-admin editors for array-index or constructor-chain access patterns targeting host built-ins.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is GHSA-hx4h-vr3m-45vh?
n8n's VM-based workflow expression engine lets an authenticated user reach a reference to a host JavaScript built-in through array-index access and pollute its prototype, crashing the shared Node.js process that runs every workflow on the instance. Because n8n runs as an AI-agent orchestration layer with 16 downstream dependents and a package risk score of 69/100, a single malicious or compromised workflow editor can take down automation and AI-agent pipelines for the entire tenant, not just their own workflow. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit/Nuclei template yet, so this reads as a low-noise disclosure rather than an actively exploited bug, but the underlying primitive (prototype pollution reachable from user-controlled expressions) is well understood and easy to weaponize once a PoC surfaces. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately; if you can't patch now, restrict workflow-creation/edit rights to fully trusted users and disable the VM expression engine where an alternative exists, since both are only partial mitigations.
Is GHSA-hx4h-vr3m-45vh actively exploited?
No confirmed active exploitation of GHSA-hx4h-vr3m-45vh has been reported, but organizations should still patch proactively.
How to fix GHSA-hx4h-vr3m-45vh?
Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 (or later) as soon as possible — this is the only full remediation. If upgrading isn't immediately feasible, restrict workflow creation/editing to fully trusted users only and disable the VM expression engine if your deployment supports a non-VM alternative; treat both as short-term, partial mitigations. For detection, monitor for unexpected n8n process crashes or restarts correlated with workflow save/edit events, and audit recent expression changes by non-admin editors for array-index or constructor-chain access patterns targeting host built-ins.
What systems are affected by GHSA-hx4h-vr3m-45vh?
This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow orchestration pipelines.
What is the CVSS score for GHSA-hx4h-vr3m-45vh?
No CVSS score has been assigned yet.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0029 Denial of AI Service AML.T0081 Modify AI Agent Configuration Compliance Controls Affected
What are the technical details?
Original Advisory
## Impact An authenticated user able to create or edit a workflow expression could abuse the expression engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process, leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected. ## Patches The issue has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Disable the VM expression engine if an alternative is available for your deployment. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Exploitation Scenario
An attacker who holds (or compromises) credentials for a low-privileged n8n editor account creates or edits a workflow expression using array-element access to reach a JavaScript host built-in via bracket-notation/constructor-chain indexing. They use that reference to pollute the built-in's prototype with attacker-controlled properties. Since the VM expression engine executes inside the same main Node.js process as the rest of n8n, the pollution corrupts shared global state and crashes or destabilizes the process — a single workflow edit takes down every workflow on the instance, including AI-agent automations other teams depend on, resulting in a denial of service.
Weaknesses (CWE)
CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.
- [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
- [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.
Source: MITRE CWE corpus.
References
- github.com/advisories/GHSA-hx4h-vr3m-45vh
- github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042f
- github.com/n8n-io/n8n/releases/tag/n8n@1.123.67
- github.com/n8n-io/n8n/releases/tag/n8n@2.31.5
- github.com/n8n-io/n8n/releases/tag/n8n@2.32.1
- github.com/n8n-io/n8n/security/advisories/GHSA-hx4h-vr3m-45vh
Timeline
Related Vulnerabilities
CVE-2026-33663 10.0 n8n: member role steals plaintext HTTP credentials
Same package: n8n CVE-2026-33660 10.0 TensorFlow: type confusion NPD in tensor conversion
Same package: n8n CVE-2026-21858 10.0 n8n: Input Validation flaw enables exploitation
Same package: n8n CVE-2026-27494 9.9 n8n: security flaw enables exploitation
Same package: n8n CVE-2026-27495 9.9 n8n: Code Injection enables RCE
Same package: n8n