Junglewise Threat Intelligence

CVE-2026-59206: n8n prototype pollution in workflow API

CVE-2026-59206 · Severity: high · CVSS 4 · Published 2026-07-09

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool used to connect various business applications. A security vulnerability allows users with basic workflow creation permissions to manipulate the system's internal configuration. This can lead to a complete bypass of authentication, allowing unauthorized access to sensitive user data (including emails and MFA status) and potentially causing the service to become unresponsive.

Technical details

A prototype pollution vulnerability exists in n8n's workflow API, specifically when saving, updating, or importing workflow credentials. An authenticated attacker with 'workflow:create' permissions can inject properties into 'Object.prototype'. This pollution can be leveraged to bypass authentication mechanisms, granting unauthenticated access to privileged endpoints such as user and project listings. Successful exploitation allows for the disclosure of personal data (email, roles, MFA status) and project details, or can lead to a Denial of Service (DoS) by corrupting the global state. The issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.

Affected products

  • n8n-io n8n < 1.123.61, >= 2.0.0-rc.0 < 2.27.4, >= 2.28.0 < 2.28.1

Timeline

  • 2026-06-24: disclosed: Initial disclosure by reporter
  • 2026-07-09: advisory: NVD publication date
  • 2026-07-22: advisory: GitHub Advisory published

References

Related threats