No analysis available yet.
No remediation available yet.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 20 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n is a workflow automation platform. In versions prior to 1.123.69, 2.33.4, and 2.34.1, the JavaScript Code node's VM sandbox did not freeze the sandbox's Function.prototype, allowing an authenticated user with the ability to create and execute workflows to pollute it from within a Code node execution and recover a reference to the host's globalThis, resulting in a sandbox escape. The full exploit chain additionally depends on specific modules being available as allowlisted imports in the deployment's configuration. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1. | |
| Title | n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-1321 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T14:53:36.111Z
Reserved: 2026-08-20T10:55:09.093Z
Link: CVE-2026-77083
Updated: 2026-08-20T14:53:33.478Z
Status : Received
Published: 2026-08-20T12:16:39.840
Modified: 2026-08-20T15:18:42.357
Link: CVE-2026-77083
No data.
OpenCVE Enrichment
No data.
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')