Junglewise Threat Intelligence

n8n prototype pollution in VM expression engine sandbox

Severity: medium · CVSS 6.1 · Published 2026-07-22

Executive brief

n8n is a workflow automation tool used to connect different software services. A vulnerability in its expression engine allows an authorized user to crash the service by manipulating internal software structures. This could lead to a total service outage for both self-hosted and cloud-based installations, disrupting automated business processes.

Technical details

A prototype pollution vulnerability exists in n8n's VM expression engine due to a sandbox escape. An authenticated attacker with permissions to create or edit workflow expressions can use array-element access to obtain a reference to a host built-in object. By polluting the prototype of these objects in the main n8n process, the attacker can trigger a denial of service (DoS) condition. The vulnerability affects both self-hosted and cloud instances using the VM expression engine. Patches are available in versions 1.123.67, 2.31.5, and 2.32.1.

Affected products

  • n8n-io n8n < 1.123.67, >= 2.0.0-rc.0 < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: advisory
  • 2026-07-22: patched

References

Related threats