CVE-2026-44789

CRITICAL LAB

n8n: HTTP Request Node Pagination Prototype Pollution to RCE

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-44789. PoCs published by BiiTts.

AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-44789, demonstrating a prototype pollution vulnerability in n8n that leads to remote code execution (RCE). The exploit chain involves polluting Object.prototype via the HTTP Request node's pagination settings and then triggering a task runner respawn to execute arbitrary commands.

Description

n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.

Exploits (1)

github WORKING POC
by BiiTts · pythonpoc
https://github.com/BiiTts/CVE-2026-44789-n8n-PrototypePollution-RCE

This repository contains a functional exploit for CVE-2026-44789, demonstrating a prototype pollution vulnerability in n8n that leads to remote code execution (RCE). The exploit chain involves polluting Object.prototype via the HTTP Request node's pagination settings and then triggering a task runner respawn to execute arbitrary commands.

Classification
Working Poc 100%
Attack Type
Rce
Complexity
Complex
Reliability
Reliable
Target: n8n < 1.123.43
Auth required
Prerequisites: Authenticated access to n8n · Task runners enabled · Ability to create and execute workflows
mistral-large-3 · analyzed Jun 30, 2026 Full analysis →

References (1)

Core 1
Core References

Scores

CVSS v3 9.9
EPSS 0.0063
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Lab Environment

COMMUNITY
Community Lab
docker pull n8nio/n8n:1.123.42

Details

CWE
CWE-1321
Status published
Products (4)
n8n/n8n < 1.123.43
n8n-io/n8n < 1.123.43
n8n-io/n8n >= 2.0.0-rc.0, < 2.20.7
n8n-io/n8n >= 2.21.0, < 2.21.1
Published Jun 23, 2026
Tracked Since Jun 23, 2026