Critical n8n Prototype Pollution Bug Enables Full Credential Theft via RCE
A critical vulnerability tracked as CVE-2026-33696 affects the n8n workflow automation platform, allowing any user with workflow edit access to achieve remote code execution as the n8n process user. The flaw stems from a prototype pollution bug in the GSuiteAdmin node, where setting a schema name to __proto__ corrupts Object.prototype and affects all plain objects created afterward. An attacker can chain a webhook, a GSuiteAdmin node, and a Git node in a single POST request to execute arbitrary commands via git's GIT_SSH_COMMAND environment variable. Because the n8n process holds the encryption key for all stored credentials, a successful exploit effectively exposes every credential in the instance. Users should upgrade to fixed versions 2.14.1, 2.13.3, or 1.123.27 and restart the service, as updating alone does not clear an already-polluted running process.
This is an AI-generated summary. ShortSingh links to the original source for the complete article.



Discussion (0)
Log in to join the discussion and vote.
Log in