n8n npm Package Vulnerability: Potential Remote Code Execution
The n8n npm package reportedly has a vulnerability where authenticated users with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter, potentially leading to remote code execution on the instance.
What happened
The n8n npm package is under investigation for a vulnerability that could allow authenticated users with permission to create or modify workflows to achieve global prototype pollution. This is reportedly done via an unvalidated pagination parameter, which could potentially lead to remote code execution on the instance. The affected versions are n8n (npm) <1.123.43, <2.20.7, and <2.22.1.
To mitigate this vulnerability, it is recommended to upgrade to n8n version 1.123.43, 2.20.7, or 2.22.1 or later. If an immediate upgrade is not possible, limiting workflow creation and editing permissions and disabling the HTTP Request node is advised. For more detailed information, consult the primary sources.
How 0Day mitigates this
n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.