Workflow Warning: The n8n CVSS 10.0 Prototype Pollution Crisis
ID: 6ae02800-1d1d-52bf-953f-4ff05e86c97f
STIX ID: report--6ae02800-1d1d-52bf-953f-4ff05e86c97f
Feed Name: securityonline.info
Two critical prototype-pollution vulnerabilities were disclosed in n8n that can lead to remote code execution: a CVSS 9.4 flaw in XML workflow handling and a CVSS 10 issue in the xml2js webhook parser. Attackers with workflow creation/edit permissions can craft malicious XML to pollute the global JavaScript object prototype and, when chained with nodes such as the Git node (SSH operations), achieve full RCE on the host. n8n has released fixes and recommends immediate upgrades, restricting workflow edit/create permissions, and excluding the XML node (n8n-nodes-base.xml) as a temporary mitigation.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
