{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3an8nn8n2.14.0node.js/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*","cpe:2.3:a:n8n:n8n:2.14.0:*:*:*:*:node.js:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-33696"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n"],"_cs_severities":["critical"],"_cs_tags":["n8n","prototype-pollution","rce"],"_cs_type":"advisory","_cs_vendors":["n8n"],"content_html":"\u003cp\u003eA critical prototype pollution vulnerability (CVE-2026-33696) exists within the GSuiteAdmin node of n8n, a workflow automation platform. This flaw enables an authenticated user, possessing the ability to create or modify workflows, to inject arbitrary values into the \u003ccode\u003eObject.prototype\u003c/code\u003e. By crafting malicious parameters during node configuration, an attacker can effectively overwrite properties of the base JavaScript object. Successful exploitation leads to remote code execution (RCE) on the n8n instance, potentially compromising sensitive data and systems. The vulnerability affects n8n versions prior to 2.14.1, 2.13.3, and 1.123.27. Defenders should prioritize upgrading n8n instances to patched versions to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker authenticates to an n8n instance with permissions to create or modify workflows.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a malicious workflow that includes a GSuiteAdmin node.\u003c/li\u003e\n\u003cli\u003eWithin the GSuiteAdmin node's configuration, the attacker injects a specially crafted parameter designed to trigger prototype pollution.\u003c/li\u003e\n\u003cli\u003eThe crafted parameter manipulates the \u003ccode\u003eObject.prototype\u003c/code\u003e by assigning attacker-controlled values.\u003c/li\u003e\n\u003cli\u003eThe n8n application processes the workflow, executing the GSuiteAdmin node with the polluted prototype.\u003c/li\u003e\n\u003cli\u003eThe prototype pollution leads to the execution of arbitrary code within the n8n instance's context.\u003c/li\u003e\n\u003cli\u003eThe attacker gains control of the n8n instance, enabling further malicious activities.\u003c/li\u003e\n\u003cli\u003eThe attacker can now use the compromised instance to access sensitive data, pivot to other systems, or deploy further attacks.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to achieve remote code execution on the n8n instance. This grants the attacker complete control over the application and the underlying server. Potential consequences include data theft, deployment of ransomware, lateral movement to other systems within the network, and disruption of critical business processes automated by n8n workflows. The number of affected organizations depends on the prevalence of vulnerable n8n instances.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n to versions 2.14.1, 2.13.3, or 1.123.27 or later to patch CVE-2026-33696.\u003c/li\u003e\n\u003cli\u003eLimit workflow creation and editing permissions to fully trusted users only, as described in the advisory.\u003c/li\u003e\n\u003cli\u003eDisable the XML node by adding \u003ccode\u003en8n-nodes-base.xml\u003c/code\u003e to the \u003ccode\u003eNODES_EXCLUDE\u003c/code\u003e environment variable, as described in the advisory.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-16T15:14:29Z","date_published":"2026-03-26T16:41:01Z","id":"https://feed.craftedsignal.io/briefs/2024-01-30-n8n-rce/","summary":"A prototype pollution vulnerability in the n8n GSuiteAdmin node allows authenticated users with workflow creation/modification permissions to achieve remote code execution (RCE) by injecting attacker-controlled values into `Object.prototype`.","title":"n8n Prototype Pollution Vulnerability Leads to Remote Code Execution","url":"https://feed.craftedsignal.io/briefs/2024-01-30-n8n-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:n8n:n8n:2.14.0:*:*:*:*:node.js:*:*","version":"https://jsonfeed.org/version/1.1"}