CVE-2026-77083: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') in n8n-io n8n
Description
CVE-2026-77083 is a prototype pollution vulnerability in the JavaScript Code node's VM sandbox of the n8n workflow automation platform. In affected versions, the sandbox does not freeze Function.prototype, allowing an authenticated user with workflow execution privileges to modify the prototype and escape the sandbox. This vulnerability requires the presence of specific allowlisted modules in the deployment configuration to complete the exploit chain. The issue is fixed in versions 1.123.69, 2.33.4, and 2.34.1.
CVSS v4.0
Score 6.0medium
Affected software
n8n-io
n8n
n8n-io
n8n
n8n-io
n8n
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability in n8n's JavaScript Code node VM sandbox allows an authenticated user who can create and execute workflows to perform prototype pollution by modifying Function.prototype, which is not frozen. This enables recovery of a reference to the host's globalThis object, resulting in sandbox escape. Exploitation depends on specific modules being allowlisted in the deployment. The flaw affects versions prior to 1.123.69, 2.33.4, and 2.34.1 and is addressed by fixes in these versions.
Potential Impact
An authenticated user with permission to create and execute workflows can exploit this vulnerability to escape the sandbox environment, potentially gaining access to the host environment's global context. This could lead to unauthorized code execution beyond the intended sandbox restrictions. The impact is limited by the need for authentication and specific deployment configurations.
Mitigation Recommendations
Upgrade n8n to version 1.123.69, 2.33.4, or 2.34.1 or later, where the vulnerability is fixed. No additional mitigation is required if these versions are in use.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-08-20T10:55:09.093Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 6a86e708acd9273b498befd6
Added to database: 08/20/2026, 11:37:44 UTC
Last enriched: 09/11/2026, 05:03:08 UTC
Last updated: 10/04/2026, 16:10:29 UTC
Views: 70
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.