Executive brief
n8n is a workflow automation tool used to connect different software services. A vulnerability in its expression engine allows an authorized user to crash the service by manipulating internal software structures. This could lead to a total service outage for both self-hosted and cloud-based installations, disrupting automated business processes.
Technical details
A prototype pollution vulnerability exists in n8n's VM expression engine due to a sandbox escape. An authenticated attacker with permissions to create or edit workflow expressions can use array-element access to obtain a reference to a host built-in object. By polluting the prototype of these objects in the main n8n process, the attacker can trigger a denial of service (DoS) condition. The vulnerability affects both self-hosted and cloud instances using the VM expression engine. Patches are available in versions 1.123.67, 2.31.5, and 2.32.1.
Affected products
- n8n-io n8n < 1.123.67, >= 2.0.0-rc.0 < 2.31.5, >= 2.32.0 < 2.32.1
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-hx4h-vr3m-45vh
- https://github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042f
- https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.67
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.31.5
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.32.1
- https://api.github.com/repos/n8n-io/n8n/security-advisories/GHSA-hx4h-vr3m-45vh