Executive brief
n8n is a workflow automation platform that allows users to create and execute automated business processes. An authenticated user with permission to create or modify workflows can exploit a prototype pollution vulnerability in the GSuiteAdmin node by supplying crafted parameters, allowing them to write arbitrary values into JavaScript object prototypes and achieve remote code execution on the n8n instance.
Technical details
This is a prototype pollution vulnerability (CWE-1321) in n8n's GSuiteAdmin and XML nodes. An authenticated user with workflow creation/modification permissions can supply specially crafted node parameters that pollute Object.prototype with attacker-controlled values. This prototype pollution can then be leveraged to achieve remote code execution on the n8n instance. The vulnerability requires authentication and workflow management permissions but does not require user interaction beyond the initial workflow modification. The issue has been patched in n8n versions 2.14.1, 2.13.3, and 1.123.27.
Affected products
- n8n n8n 2.14.0 (2.14.1 fixed), 2.0.0-rc.0 to 2.13.2 (2.13.3 fixed), all versions before 1.123.27
Timeline
- 2026-03-25: disclosed: Published on GitHub Security Advisory
- 2026-03: patched: Fixed in versions 2.14.1, 2.13.3, and 1.123.27