Impact
The vulnerability is a prototype pollution flaw in n8n's Instance AI workflow summary. A malicious workflow submitted through the REST API can include keys such as __proto__ or constructor, which are used as ordinary object keys in the summarization function. These nested writes overwrite Object.prototype in the running n8n process, corrupting internal state and causing subsequent requests to fail. The flaw is classified as CWE‑1321 and results in a denial‑of‑service condition; it does not grant code execution or data disclosure. Attackers can exploit the flaw by sending a crafted workflow to the exposed API endpoint, as the description does not mention any additional authentication constraints, so the likely attack vector is a web‑application or API‑level exploitation.
Affected Systems
n8n, an open‑source workflow automation platform developed by n8n‑io, is affected when versions older than 2.37.7 or 2.38.2 are deployed. These releases were identified by the CNA before the fix was released.
Risk and Exploitability
The CVSS score of 6.0 indicates a moderate risk, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. If the REST API is reachable by an attacker—either through an exposed endpoint or insufficient network segmentation—exploitability is relatively high because the flaw can be triggered with a simple POST request containing the offending keys. Once triggered, the n8n process becomes unable to handle subsequent API calls, effectively denying service to legitimate users. Adequate mitigations, such as limiting API access, can reduce the chance of exploitation.
OpenCVE Enrichment
Github GHSA