n8n: HTTP Request Node Pagination Prototype Pollution to RCE
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2026-44789. PoCs published by BiiTts.
AI-analyzed exploit summary This repository contains a functional exploit for CVE-2026-44789, demonstrating a prototype pollution vulnerability in n8n that leads to remote code execution (RCE). The exploit chain involves polluting Object.prototype via the HTTP Request node's pagination settings and then triggering a task runner respawn to execute arbitrary commands.
Description
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, an authenticated user with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter in the HTTP Request node. Combined with other techniques this could lead to RCE on the instance. This vulnerability is fixed in 1.123.43, 2.22.1, and 2.20.7.
Exploits (1)
This repository contains a functional exploit for CVE-2026-44789, demonstrating a prototype pollution vulnerability in n8n that leads to remote code execution (RCE). The exploit chain involves polluting Object.prototype via the HTTP Request node's pagination settings and then triggering a task runner respawn to execute arbitrary commands.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H