No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 20 Aug 2026 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 20 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authenticated user with Code node access to exploit prototype pollution to execute arbitrary commands within the runner container. Because the polluted prototype is a process-wide object, the corruption persists across other tenants' Code node executions on the same shared runner. On v1.x instances without task runners enabled, Code node JavaScript runs directly in the main n8n process, where the impact could be higher. | |
| Title | n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T15:44:34.323Z
Reserved: 2026-08-20T10:51:39.784Z
Link: CVE-2026-77077
Updated: 2026-08-20T15:44:27.484Z
Status : Received
Published: 2026-08-20T12:16:39.127
Modified: 2026-08-20T16:18:33.910
Link: CVE-2026-77077
No data.
OpenCVE Enrichment
No data.