CVE-2026-42231Disclosure(n8n / n8n)

LOWCVSS 8.8 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch n8n n8n systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n8n's webhook handler allowed prototype pollution via a crafted XML payload. An authenticated user with permission to create or modify workflows could exploit this to pollute the JavaScript object prototype and, by chaining the pollution with the Git node's SSH operations, achieve remote code execution on the n8n host. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

2.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-1321

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Public PoC is present in monitored signal
  • Patch or workaround signal is available
  • 11 mentions across 9 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 3 signals
  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 8 signals
  • Disclosure: 6 classified signals
  • Peaked 6d ago at 2 mentions (2026-05-04); latest day: 1
  • 11 total mentions across 9 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline11 mentions / 9d
01122Mentions · 2026-04-27: 1Mentions · 2026-04-29: 1Mentions · 2026-05-04: 2Mentions · 2026-05-05: 2Mentions · 2026-05-11: 1Mentions · 2026-05-13: 1Mentions · 2026-05-18: 1Mentions · 2026-05-19: 1Mentions · 2026-06-11: 1PoC Mentioned / Linked · 2026-04-27: 1PoC Mentioned / Linked · 2026-05-11: 1PoC Mentioned / Linked · 2026-05-13: 1Patch / Workaround · 2026-04-29: 1Patch / Workaround · 2026-05-05: 1Technical Details · 2026-04-27: 1Technical Details · 2026-04-29: 1Technical Details · 2026-05-04: 2Technical Details · 2026-05-05: 2Technical Details · 2026-05-18: 1Technical Details · 2026-05-19: 104-2704-2905-0405-0505-1105-1305-1805-1906-11
Signal classification4 categories
Disclosure
654.5%
Patch
218.2%
PoC
218.2%
General
19.1%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-04-271
Disclosure1
2026-04-291
Patch1
2026-05-042
Disclosure2
2026-05-052
Disclosure1Patch1
2026-05-111
PoC1
2026-05-131
PoC1
2026-05-181
Disclosure1
2026-05-191
Disclosure1
2026-06-111
General1
Full discourse11 posts
  • Netlas.io@Netlas_io
    Disclosure

    CVE-2026-42231 and CVE-2026-42232: Two Prototype Pollution vulnerabilities in n8n, 9.4 & 10.0 rating 🔥🔥 Two recently disclosed Prototype Pollution vulnerabilities in n8n allow an authenticated attacker to execute arbitrary code on the server. 👉 https://nt.ls/beZWa

    Post summary

    Two newly disclosed prototype‑pollution CVEs (CVE‑2026‑42231 & CVE‑2026‑42232) affect n8n 9.4 and 10.0, enabling authenticated attackers to run arbitrary code on the server. The post lacks patch information, active exploitation evidence, or detailed exploit code.

    060104997
    7.6K followersView on X
  • Upwind Security MDR@UpwindMDR
    Patch

    🚨 CVE-2026-42231 – n8n RCE (Critical) Prototype pollution in XML webhook parser → Remote Code Execution ⚠️ Auth user → full host compromise Patch ASAP 📎 https://github.com/advisories/GHSA-q5f4-99jv-pgg5 #AppSec #RCE #CVE

    Post summary

    The tweet announces a critical RCE vulnerability (CVE‑2026‑42231) in n8n, highlights prototype‑pollution details, and urges immediate patching without mentioning exploits or active attacks.

    00040148
    237 followersView on X
  • CCB Alert@CCBalert
    Patch

    Warning: Critical Prototype Pollution in #n8n. #CVE-2026-42231 & #CVE-2026-42232, CVSS: 9.4. An authenticated attacker can exploit the XML parsers and achieve complete remote code execution #RCE! #Patch #Patch #Patch More info: https://ccb.belgium.be/advisories/warning-critical-vulnerabilities-n8n-patch-immediately-0

    Post summary

    A critical n8n prototype‑pollution vulnerability (CVE‑2026‑42231/32) allows authenticated attackers to achieve remote code execution; an advisory urges immediate patching.

    01011273
    7.2K followersView on X
  • إبراهيم بوحيمد | Ibrahim Buhaimed@buhaimedi
    Disclosure

    📍 CVE-2026-42231 ـ (Prototype Pollution) في xml2js المستخدم داخل webhook handler لمعالجة XML request bodies. المهاجم يحتاج حساب عنده صلاحية إنشاء أو تعديل workflows. يرسل XML payload مصمم بطريقة معينه . إذا تم ربطها مع Git Node SSH operations، قد تصل إلى RCE على سيرفر n8n.

    Post summary

    CVE‑2026‑42231 is a prototype‑pollution flaw in n8n’s xml2js‑based webhook handler that, when combined with Git Node SSH operations and sufficient workflow‑editor privileges, can potentially cause remote code execution.

    10010211
    49.3K followersView on X
  • TodayInCyber@TodayInCyberIO
    Disclosure

    4/5 n8n: five critical vulnerabilities tied to prototype pollution and code execution (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791).

    Post summary

    The post announces five critical prototype pollution vulnerabilities in n8n (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) that result in code execution.

    100104
    8 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42231 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n… https://www.cve.org/CVERecord?id=CVE-2026-42231

    Post summary

    The post announces that CVE-2026-42231 is a flaw in n8n's xml2js library affecting earlier releases, with specific vulnerable versions identified.

    00010153
    57.4K followersView on X
  • IntegSec@integ_sec
    General

    CVE-2026-42231: n8n Workflow Automation Prototype Pollution - What It Means for Your Business and How to Respond https://hubs.li/Q04l24850

    Post summary

    The article announces the n8n Workflow Automation prototype pollution vulnerability (CVE-2026-42231) and offers general guidance on potential business impacts without detailing technical aspects or mitigation steps.

    0000033
    31 followersView on X
  • cySalazar@cySalazar666
    PoC

    n8n in uno stack agentic non è "automation". È il punto in cui un LLM compromesso eredita le OAuth verso tutto il SaaS aziendale. CVE-2026-42231 con PoC pubblico = pivot point pronto all'uso.

    Post summary

    A public PoC has been released for CVE-2026-42231, enabling OAuth credential inheritance for compromised LLMs within n8n.

    0000010
    13 followersView on X
  • Hephaestvs@Vulcanux_
    PoC

    csirt_it: ‼ #PoC: Proof of Concept per lo sfruttamento della vulnerabilità CVE-2026-42231 relativa a #n8n, risulta disponibile in rete Rischio: 🟠 🔗 https://www.acn.gov.it/portale/w/n8n-poc-pubblico-per-lo-sfruttamento-della-cve-2026-42231 ⚠ Importante aggiornare i prodotti interessati https://t.co/xTMovuvjyo

    Post summary

    The tweet announces that a Proof of Concept for CVE-2026-42231 on n8n is publicly available and urges users to update their products.

    0000048
    613 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42231 Prototype Pollution Leading to Remote Code Execution in n8n Versions Before 1.123.32 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42231

    Post summary

    The text announces a new CVE (CVE-2026-42231) describing a prototype‑pollution vulnerability that permits remote code execution in n8n versions prior to 1.123.32, but no PoC, exploit code, patch, or active exploitation claim is provided.

    0000047
    4.0K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-42231 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the xml2js library used to parse XML request bodies in n… https://www.cve.org/CVERecord?id=CVE-2026-42231 ----- Traducción: CVE-2026-42231 n8n… http://infoflow.cloud`

    Post summary

    The post announces CVE-2026-42231, noting a flaw in n8n’s XML parsing via xml2js, but does not provide PoC, exploit details, patches, or evidence of active exploitation.

    0000032
    75 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.18.0node.js-

Explore more