Impact
n8n versions prior to 1.123.67, 2.31.5, and 2.32.1 are vulnerable to a prototype pollution flaw in the VM expression engine. The flaw allows an authenticated user who can create or edit a workflow expression to manipulate array-element access, obtain a reference to a host built‑in object, and pollute its prototype in the main n8n process. This sandbox escape can lead to a denial of service by corrupting runtime data structures.
Affected Systems
Affected systems include all self‑hosted and cloud deployments of n8n running any of the vulnerable releases: n8n 1.x prior to 1.123.67, n8n 2.31.x prior to 2.31.5, and n8n 2.32.x prior to 2.32.1. The vulnerability is not limited to a specific operating system or environment.
Risk and Exploitability
The CVSS score of 6.1 indicates a moderate severity. The EPSS score is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. An attacker must be authenticated to create or edit a workflow expression, after which the prototype pollution can escape the sandbox. No public exploit is known, but the ability to cause a denial of service could be leveraged in a broader attack context.
OpenCVE Enrichment