Description
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process and disrupt later requests. The affected function is summarizeWorkflowStructure in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts. This issue is fixed in versions 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 6 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

The vulnerability is a prototype pollution flaw in n8n's Instance AI workflow summary. A malicious workflow submitted through the REST API can include keys such as __proto__ or constructor, which are used as ordinary object keys in the summarization function. These nested writes overwrite Object.prototype in the running n8n process, corrupting internal state and causing subsequent requests to fail. The flaw is classified as CWE‑1321 and results in a denial‑of‑service condition; it does not grant code execution or data disclosure. Attackers can exploit the flaw by sending a crafted workflow to the exposed API endpoint, as the description does not mention any additional authentication constraints, so the likely attack vector is a web‑application or API‑level exploitation.

Affected Systems

n8n, an open‑source workflow automation platform developed by n8n‑io, is affected when versions older than 2.37.7 or 2.38.2 are deployed. These releases were identified by the CNA before the fix was released.

Risk and Exploitability

The CVSS score of 6.0 indicates a moderate risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. If the REST API is reachable by an attacker—either through an exposed endpoint or insufficient network segmentation—exploitability is relatively high because the flaw can be triggered with a simple POST request containing the offending keys. Once triggered, the n8n process becomes unable to handle subsequent API calls, effectively denying service to legitimate users. Adequate mitigations, such as limiting API access, can reduce the chance of exploitation.

Generated by OpenCVE AI on September 9, 2026 at 08:40 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to n8n v2.37.7, v2.38.2, or a later release where the summarizeWorkflowStructure function has been hardened to reject keys that may pollute the prototype.
  • If an upgrade is not immediately possible, configure the API layer or reverse proxy to block or reject any payload that contains "__proto__" or "constructor" as top‑level keys in workflow definitions.
  • Restrict access to the n8n REST API to trusted networks or authenticated users, and enforce strict input validation to prevent injection of prototype‑polluting keys.
  • Monitor audit logs for unusual workflow submissions that contain prototype‑polluting keys, and alert administrators when such patterns are detected.

Generated by OpenCVE AI on September 9, 2026 at 08:40 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-679f-58pq-4v2c n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process and disrupt later requests. The affected function is summarizeWorkflowStructure in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts. This issue is fixed in versions 2.37.7 and 2.38.2.
Title n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
Weaknesses CWE-1321
References
Metrics cvssV4_0

{'score': 6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T16:03:58.476Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86078

cve-icon Vulnrichment

Updated: 2026-09-09T15:49:55.725Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:16.677

Modified: 2026-09-11T18:21:20.657

Link: CVE-2026-86078

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:00Z

Weaknesses
  • CWE-1321

    Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')