Junglewise Threat Intelligence

CVE-2026-72749: n8n before 1.123.67, 2.31.5, and 2.32.1 contains a prototype pollution vulnerability in the Edit Fields (Set) node. The node assigns output

CVE-2026-72749 · Severity: medium · CVSS 6.5 · Published 2026-08-11

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to create and execute automated tasks. An authenticated user can exploit a flaw in the Edit Fields (Set) node to corrupt shared memory in the application's core process, causing the instance to reject all authentication requests and forcing a complete service outage until the application is manually restarted. This affects all users on the instance simultaneously.

Technical details

The vulnerability is a prototype pollution flaw in n8n's Edit Fields (Set) node, which uses unsafe dot-notation path assignment to set output field names without proper validation. An authenticated attacker can supply a field name matching an inherited built-in method path (e.g., a prototype chain property) to corrupt a shared global object in the Node.js process. Because this corrupted global is used during request authentication, all subsequent authenticated API requests fail with HTTP 500 errors, denying service to all users until process restart. The attack requires authentication and network access but no special user interaction. Patches are available in versions 1.123.67, 2.31.5, 2.32.1 and later.

Affected products

  • n8n n8n prior to 1.123.67, 2.0.0-rc.0 through 2.31.4, 2.32.0

Timeline

  • 2026-07-22: disclosed

References

Related threats