Impact
The vulnerability is a prototype pollution flaw located in the Edit Fields (Set) node of n8n. An authenticated user can assign an output field name that triggers a dot-notation path setter to overwrite a global property used by Node.js's request‑authentication logic. This corruption causes the instance to reject every incoming authenticated request, effectively denying service to all users until the process is restarted. The weakness is a classic Prototype Pollution (CWE‑1321).
Affected Systems
n8n-io publishes the affected product under the n8n family. Versions prior to 1.123.67, 2.31.5, and 2.32.1 are vulnerable. The flaw impacts the Node.js runtime that runs the n8n instance and the Edit Fields (Set) node configuration, and any user who can authenticate to the instance may exercise the attack.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity. EPSS has no available value, so the exploitation probability is not quantified here. The vulnerability is not listed in the CISA KEV catalog. Attack requires authenticated access to the n8n instance and is limited to users who can create or modify fields in the Edit Fields node. The impact is complete denial for all authenticated users until a restart or patch is applied.
OpenCVE Enrichment