A critical vulnerability has been identified in the n8n workflow automation platform, affecting versions prior to 1.123.43, 2.22.1, and 2.20.7. The vulnerability arises from an unvalidated pagination parameter in the HTTP Request node, which allows an authenticated user with workflow creation or modification permissions to achieve global prototype pollution. This can be combined with other techniques to result in remote code execution (RCE) on the affected instance. The CVSS score of 9.9 reflects the high severity of this issue, as it enables attackers to execute arbitrary code with the privileges of the affected system. Organizations using n8n in their infrastructure should prioritize upgrading to the patched versions to mitigate this risk. The vulnerability does not require user interaction beyond the initial authentication, making it particularly dangerous in environments where users have workflow management permissions. Immediate action is recommended to prevent potential compromise of systems running the affected versions of n8n.
CRITICAL
CVSS 9.9
CVE-2026-44789
2026-08-25
Critical Vulnerability in n8n Allows Remote Code Execution via Prototype Pollution (CVE-2026-44789)
A critical vulnerability in n8n (CVE-2026-44789) allows authenticated users to achieve global prototype pollution through an unvalidated pagination parameter, potentially leading to RCE. Affected versions are prior to 1.123.43, 2.22.1, and 2.20.7.