Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77077— n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution

Quick assessment

Affected
n8n-io n8n
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

n8n 在 1.123.69 之前、2.33.4 之前以及 2.34.1 之前的版本中存在一个 JavaScript 任务运行器虚拟机沙箱逃逸漏洞。该运行器的原型冻结流程仅覆盖 globalThis 上的函数,而未包括内部模块构造函数(如 EventEmitter),从而导致已认证且具有 Code 节点访问权限的用户可通过原型污染,在运行器容器内执行任意命令。由于被污染的原型是一个进程级对象,因此这种损坏会在同一共享运行器上影响其他租户执行 Code 节点的操作。在未启用任务运行器的 v1.x 实例中,Code 节

CVSS 7.2 · High EPSS 0.36% · P29

Affected Version Matrix 6

VendorProduct Version RangeStatus
n8n-io n8n < 1.123.69 affected
1.123.69 unaffected
2.34.0< 2.34.1 affected
2.34.1 unaffected
2.0.0< 2.33.4 affected
2.33.4 unaffected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77077

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
n8n before 1.123.69 Remote Code Execution via EventEmitter Prototype Pollution
Source: CVE Program / CVE List V5
Vulnerability Description
n8n versions before 1.123.69, 2.33.4, and 2.34.1 contain a JavaScript task runner VM sandbox escape. The runner's prototype-freezing routine covers globalThis functions but not internal module constructors such as EventEmitter, allowing an authenticated user with Code node access to exploit prototype pollution to execute arbitrary commands within the runner container. Because the polluted prototype is a process-wide object, the corruption persists across other tenants' Code node executions on the same shared runner. On v1.x instances without task runners enabled, Code node JavaScript runs directly in the main n8n process, where the impact could be higher.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N
Source: CVE Program / CVE List V5
Vulnerability Type
对生成代码的控制不恰当(代码注入)
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
n8n-io n8n 0 ~ 1.123.69 -
n8n-io n8n 2.34.0 ~ 2.34.1 -
n8n-io n8n 2.0.0 ~ 2.33.4 -

II. Public POCs for CVE-2026-77077

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77077

登录查看更多情报信息。

Vendor Advisories for CVE-2026-77077 (1)

News Coverage for CVE-2026-77077 (1)

Same Patch Batch · n8n-io · 2026-08-20 · 17 CVEs total

CVE-2026-77080 8.7 HIGH n8n before 1.123.69 Arbitrary File Read and Write via Snowflake
CVE-2026-77068 8.7 HIGH n8n before 2.34.1 Remote Code Execution via Path Traversal
CVE-2026-77075 8.4 HIGH n8n before 1.123.69 Expression Injection via Resource Locator
CVE-2026-77072 8.4 HIGH n8n before 1.123.69 Stored XSS via Form Completion Page
CVE-2026-77084 7.7 HIGH n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values
CVE-2026-77079 7.4 HIGH n8n before 2.34.1 Authorization Bypass via Custom Role Deletion
CVE-2026-77071 7.1 HIGH n8n before 1.123.69 PostgREST Filter Injection via Supabase
CVE-2026-77076 7.1 HIGH n8n before 1.123.69 Credential Leak via GraphQL Node Error
CVE-2026-77070 7.1 HIGH n8n before 1.123.69 NoSQL Injection via MongoDB Node
CVE-2026-77085 6.3 MEDIUM n8n before 2.34.1 SSRF Protection Bypass via SearXNG Tool
CVE-2026-77083 6.0 MEDIUM n8n before 1.123.69 Code Node Sandbox Escape via Function.prototype Pollution
CVE-2026-77074 6.0 MEDIUM n8n before 1.123.69 SSRF via Edit Image Node
CVE-2026-77073 5.3 MEDIUM n8n before 2.34.1 Cross-Project Credential Access via MCP
CVE-2026-77082 5.3 MEDIUM n8n before 1.123.69 ReDoS via Filter and Switch Node
CVE-2026-77081 5.1 MEDIUM n8n before 1.123.69 Allowed-Domains Bypass via GraphQL Node
CVE-2026-77069 2.3 LOW n8n before 1.123.69 SSRF Protection Bypass via OAuth2

IV. Related Vulnerabilities

V. Comments for CVE-2026-77077

No comments yet


Leave a comment