Netlas.io[verified]@Netlas_ioDisclosure
Two newly disclosed prototype‑pollution CVEs (CVE‑2026‑42231 & CVE‑2026‑42232) affect n8n 9.4 and 10.0, enabling authenticated attackers to run arbitrary code on the server. The post lacks patch information, active exploitation evidence, or detailed exploit code.
Upwind Security MDR[verified]@UpwindMDRPatch
The tweet announces a critical RCE vulnerability (CVE‑2026‑42231) in n8n, highlights prototype‑pollution details, and urges immediate patching without mentioning exploits or active attacks.
إبراهيم بوحيمد | Ibrahim Buhaimed[verified]@buhaimediDisclosure
CVE‑2026‑42231 is a prototype‑pollution flaw in n8n’s xml2js‑based webhook handler that, when combined with Git Node SSH operations and sufficient workflow‑editor privileges, can potentially cause remote code execution.
TodayInCyber[verified]@TodayInCyberIODisclosure
The post announces five critical prototype pollution vulnerabilities in n8n (CVE-2026-42231, CVE-2026-42232, CVE-2026-44789, CVE-2026-44790, CVE-2026-44791) that result in code execution.
IntegSec[verified]@integ_secGeneral
The article announces the n8n Workflow Automation prototype pollution vulnerability (CVE-2026-42231) and offers general guidance on potential business impacts without detailing technical aspects or mitigation steps.
CCB Alert@CCBalertPatch
A critical n8n prototype‑pollution vulnerability (CVE‑2026‑42231/32) allows authenticated attackers to achieve remote code execution; an advisory urges immediate patching.
CVE@CVEnewDisclosure
The post announces that CVE-2026-42231 is a flaw in n8n's xml2js library affecting earlier releases, with specific vulnerable versions identified.
cySalazar@cySalazar666PoC
A public PoC has been released for CVE-2026-42231, enabling OAuth credential inheritance for compromised LLMs within n8n.