logo

Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis

ID: 6ae02800-1d1d-52bf-953f-4ff05e86c97f

STIX ID: report--6ae02800-1d1d-52bf-953f-4ff05e86c97f

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-04-24

Date Updated: 2026-04-24

Author: Ddos

...
...

Two critical prototype-pollution vulnerabilities were disclosed in n8n that can lead to remote code execution: a CVSS 9.4 flaw in XML workflow handling and a CVSS 10 issue in the xml2js webhook parser. Attackers with workflow creation/edit permissions can craft malicious XML to pollute the global JavaScript object prototype and, when chained with nodes such as the Git node (SSH operations), achieve full RCE on the host. n8n has released fixes and recommends immediate upgrades, restricting workflow edit/create permissions, and excluding the XML node (n8n-nodes-base.xml) as a temporary mitigation.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.