
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33696 is a prototype pollution vulnerability in the n8n open-source workflow automation platform, specifically affecting the XML and GSuiteAdmin nodes. An authenticated user with permission to create or modify workflows can supply crafted node configuration parameters to write attacker-controlled values onto Object.prototype, ultimately enabling remote code execution (RCE) on the n8n instance. Affected versions include all releases prior to 1.123.27 (v1 branch), 2.0.0-rc.0 through 2.13.2 (v2 branch), and version 2.14.0 specifically. The vulnerability was published on March 25, 2026, with patches released the same day. It carries a CVSS v4.0 base score of 9.4 (Critical) and a CVSS v3.1 base score of 8.8 (High) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-1321 (Improperly Controlled Modification of Object Prototype Attributes — 'Prototype Pollution'). The vulnerability exists because the XML and GSuiteAdmin nodes in n8n do not properly sanitize or restrict user-supplied parameters during node configuration, allowing an attacker to inject keys such as __proto__ or constructor.prototype into objects processed by the platform. By polluting Object.prototype with attacker-controlled values, the attacker can influence the behavior of JavaScript objects across the entire Node.js runtime, which can be chained to achieve RCE. Exploitation requires network access and low-privilege authenticated credentials (workflow creation or editing permissions), with no user interaction needed (GitHub Advisory, n8n Security Advisory).
Successful exploitation grants an attacker full remote code execution on the n8n server, resulting in complete compromise of confidentiality, integrity, and availability of the affected system. An attacker could exfiltrate sensitive workflow data and credentials stored within n8n, tamper with or delete automation workflows, and use the compromised server as a pivot point for lateral movement within the broader infrastructure. The CVSS v4.0 scoring reflects high impact on both the vulnerable system and subsequent systems, underscoring the potential for cascading damage beyond the n8n instance itself (GitHub Advisory, Feedly).
As of the time of disclosure, there is no public proof-of-concept exploit code and no confirmed evidence of in-the-wild exploitation (Feedly). The EPSS score is approximately 0.21–0.33%, placing it in the 44th percentile for exploitation likelihood within 30 days (GitHub Advisory). No threat actor attribution has been reported, and the vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, the low attack complexity and the broad deployment of n8n in enterprise automation environments make this an attractive target.
__proto__, constructor, or prototype with attacker-controlled values).Object.prototype within the Node.js runtime.alasql or similar libraries) to escalate from prototype pollution to arbitrary command execution on the server (GitHub Advisory, AnonHaven).Object.prototype manipulation or JavaScript runtime anomalies in server logs.sh, bash, curl, wget, python, nc); unexpected network listeners opened by the n8n process.__proto__, constructor, or prototype; newly created workflows by non-administrative users containing XML or GSuiteAdmin nodes with complex nested parameter structures.Users should upgrade n8n to one of the patched versions: 2.14.1, 2.13.3, or 1.123.27 (or any later release). If immediate upgrading is not possible, two temporary mitigations are available: (1) restrict workflow creation and editing permissions to fully trusted users only, and (2) disable the XML node by adding n8n-nodes-base.xml to the NODES_EXCLUDE environment variable. Note that these workarounds do not fully eliminate the risk — they reduce the attack surface but do not address the GSuiteAdmin node vector — and should only be used as short-term measures while planning for patching (n8n Security Advisory, GitHub Advisory).
Heise Online covered the vulnerability, describing it as one of two critical RCE vulnerabilities threatening the n8n automation platform and urging immediate patching (Heise). The Belgian Centre for Cybersecurity (CCB) issued an advisory warning of critical vulnerabilities in n8n and recommending immediate patching (CCB Belgium). The vulnerability was discussed on Reddit's r/blueteamsec community and referenced in The Hacker News weekly recap, indicating moderate security community interest (Reddit, The Hacker News). Greenbone included it in their March 2026 threat report as a notable critical risk (Greenbone).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."