GHSA-hx4h-vr3m-45vh: n8n: prototype pollution in expression engine causes DoS

GHSA-hx4h-vr3m-45vh MEDIUM
Published July 22, 2026
CISO Take

n8n's VM-based workflow expression engine lets an authenticated user reach a reference to a host JavaScript built-in through array-index access and pollute its prototype, crashing the shared Node.js process that runs every workflow on the instance. Because n8n runs as an AI-agent orchestration layer with 16 downstream dependents and a package risk score of 69/100, a single malicious or compromised workflow editor can take down automation and AI-agent pipelines for the entire tenant, not just their own workflow. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit/Nuclei template yet, so this reads as a low-noise disclosure rather than an actively exploited bug, but the underlying primitive (prototype pollution reachable from user-controlled expressions) is well understood and easy to weaponize once a PoC surfaces. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately; if you can't patch now, restrict workflow-creation/edit rights to fully trusted users and disable the VM expression engine where an alternative exists, since both are only partial mitigations.

Sources: GitHub Advisory CISA KEV OpenSSF ATLAS

What is the risk?

Rated medium severity by the advisory with no published CVSS vector. Exploitation requires an authenticated account with workflow create/edit rights, which limits the exposure surface compared to unauthenticated bugs but is a low bar in typical multi-user or multi-team n8n deployments where several people routinely get editor access. No active-exploitation signals exist: not in CISA KEV, no EPSS score, no public exploit code, no Nuclei template, so near-term opportunistic risk is low. The package's broader risk posture is elevated (166 other CVEs on record, OpenSSF Scorecard 6.6/10), which argues for a generally tighter patch cadence on n8n regardless of this specific issue.

How does the attack unfold?

Initial Access
Attacker uses an existing or compromised authenticated account with workflow create/edit permissions on the n8n instance.
AML.T0012
Exploitation
Attacker crafts a workflow expression that abuses array-element access in the VM expression engine to obtain a reference to a host JavaScript built-in.
Prototype Pollution
Attacker mutates the built-in's prototype, corrupting shared global state within the main n8n process.
AML.T0081
Impact
The polluted prototype destabilizes or crashes the main process, causing a denial of service across all workflows and AI-agent automations running on the instance.
AML.T0029

What systems are affected?

Package Ecosystem Vulnerable Range Patched
n8n npm < 1.123.67 1.123.67
206.1K OpenSSF 6.7 Pushed 5d ago 53% patched ~5d to patch Full package profile →

Do you use n8n? You're affected.

How severe is it?

CVSS 3.1
N/A
EPSS
N/A
Exploitation Status
No known exploitation
Sophistication
Moderate

What should I do?

1 step
  1. Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 (or later) as soon as possible — this is the only full remediation. If upgrading isn't immediately feasible, restrict workflow creation/editing to fully trusted users only and disable the VM expression engine if your deployment supports a non-VM alternative; treat both as short-term, partial mitigations. For detection, monitor for unexpected n8n process crashes or restarts correlated with workflow save/edit events, and audit recent expression changes by non-admin editors for array-index or constructor-chain access patterns targeting host built-ins.

How is it classified?

Which compliance frameworks are affected?

This CVE is relevant to:

EU AI Act
Article 15 - Accuracy, robustness and cybersecurity
NIST AI RMF
MANAGE-4.1 - Risk treatment and monitoring for deployed AI systems
OWASP LLM Top 10
LLM10:2025 - Unbounded Consumption

Frequently Asked Questions

What is GHSA-hx4h-vr3m-45vh?

n8n's VM-based workflow expression engine lets an authenticated user reach a reference to a host JavaScript built-in through array-index access and pollute its prototype, crashing the shared Node.js process that runs every workflow on the instance. Because n8n runs as an AI-agent orchestration layer with 16 downstream dependents and a package risk score of 69/100, a single malicious or compromised workflow editor can take down automation and AI-agent pipelines for the entire tenant, not just their own workflow. There is no CVSS score, EPSS data, CISA KEV listing, or public exploit/Nuclei template yet, so this reads as a low-noise disclosure rather than an actively exploited bug, but the underlying primitive (prototype pollution reachable from user-controlled expressions) is well understood and easy to weaponize once a PoC surfaces. Patch to n8n 1.123.67, 2.31.5, or 2.32.1 immediately; if you can't patch now, restrict workflow-creation/edit rights to fully trusted users and disable the VM expression engine where an alternative exists, since both are only partial mitigations.

Is GHSA-hx4h-vr3m-45vh actively exploited?

No confirmed active exploitation of GHSA-hx4h-vr3m-45vh has been reported, but organizations should still patch proactively.

How to fix GHSA-hx4h-vr3m-45vh?

Upgrade to n8n 1.123.67, 2.31.5, or 2.32.1 (or later) as soon as possible — this is the only full remediation. If upgrading isn't immediately feasible, restrict workflow creation/editing to fully trusted users only and disable the VM expression engine if your deployment supports a non-VM alternative; treat both as short-term, partial mitigations. For detection, monitor for unexpected n8n process crashes or restarts correlated with workflow save/edit events, and audit recent expression changes by non-admin editors for array-index or constructor-chain access patterns targeting host built-ins.

What systems are affected by GHSA-hx4h-vr3m-45vh?

This vulnerability affects the following AI/ML architecture patterns: agent frameworks, workflow orchestration pipelines.

What is the CVSS score for GHSA-hx4h-vr3m-45vh?

No CVSS score has been assigned yet.

What is the AI security impact?

Affected AI Architectures

agent frameworksworkflow orchestration pipelines

MITRE ATLAS Techniques

AML.T0029 Denial of AI Service
AML.T0081 Modify AI Agent Configuration

Compliance Controls Affected

EU AI Act: Article 15
NIST AI RMF: MANAGE-4.1
OWASP LLM Top 10: LLM10:2025

What are the technical details?

Original Advisory

## Impact An authenticated user able to create or edit a workflow expression could abuse the expression engine's array-element access to obtain a reference to a host built-in and pollute its prototype in the main n8n process, leading to a denial of service. Both self-hosted and cloud instances running the VM expression engine are affected. ## Patches The issue has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Disable the VM expression engine if an alternative is available for your deployment. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Exploitation Scenario

An attacker who holds (or compromises) credentials for a low-privileged n8n editor account creates or edits a workflow expression using array-element access to reach a JavaScript host built-in via bracket-notation/constructor-chain indexing. They use that reference to pollute the built-in's prototype with attacker-controlled properties. Since the VM expression engine executes inside the same main Node.js process as the rest of n8n, the pollution corrupts shared global state and crashes or destabilizes the process — a single workflow edit takes down every workflow on the instance, including AI-agent automations other teams depend on, resulting in a denial of service.

Weaknesses (CWE)

CWE-1321 — Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution'): The product receives input from an upstream component that specifies attributes that are to be initialized or updated in an object, but it does not properly control modifications of attributes of the object prototype.

  • [Implementation] By freezing the object prototype first (for example, Object.freeze(Object.prototype)), modification of the prototype becomes impossible.
  • [Architecture and Design] By blocking modifications of attributes that resolve to object prototype, such as proto or prototype, this weakness can be mitigated.

Source: MITRE CWE corpus.

Timeline

Published
July 22, 2026
Last Modified
July 22, 2026
First Seen
July 23, 2026

Related Vulnerabilities