Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 08 Sep 2026 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the Instance AI workflow summary used node names and connection keys from stored workflows as ordinary object keys. A workflow submitted through the REST API could contain __proto__ or constructor, causing nested writes to reach Object.prototype in the main n8n process and disrupt later requests. The affected function is summarizeWorkflowStructure in packages/@n8n/instance-ai/src/tools/workflows/summarize-workflow.ts. This issue is fixed in versions 2.37.7 and 2.38.2. | |
| Title | n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service | |
| Weaknesses | CWE-1321 | |
| References |
| |
| Metrics |
cvssV4_0
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-09-08T21:27:21.351Z
Reserved: 2026-09-04T19:34:03.100Z
Link: CVE-2026-86078
No data.
Status : Received
Published: 2026-09-08T22:19:16.677
Modified: 2026-09-08T22:19:16.677
Link: CVE-2026-86078
No data.
OpenCVE Enrichment
No data.
-
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')