PT-2026-40933 · N8N · N8N

Published

2026-05-14

·

Updated

2026-05-21

·

CVE-2026-44789

CVSS v4.0

9.4

Critical

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.43 n8n versions prior to 2.20.7 n8n versions prior to 2.22.1
Description An authenticated user with permissions to create or modify workflows can achieve global prototype pollution through an unvalidated pagination parameter in the HTTP Request node. Prototype pollution occurs when an application allows an attacker to modify the prototype of a base object, potentially altering the behavior of all objects created from that prototype. This issue can be combined with other techniques to result in Remote Code Execution (RCE) on the instance.
Recommendations Update to version 1.123.43 or later. Update to version 2.20.7 or later. Update to version 2.22.1 or later. Limit workflow creation and editing permissions to fully trusted users only. Disable the HTTP Request node by adding n8n-nodes-base.httpRequest to the NODES EXCLUDE environment variable.

Fix

Prototype Pollution

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-44789
GHSA-C8XV-5998-G76H

Affected Products

N8N