NPM · MAY 2026 · EARLY WARNING

n8n npm Package Vulnerability: Potential Remote Code Execution

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-C8XV-5998-G76HSeverity: HIGH

The n8n npm package reportedly has a vulnerability where authenticated users with permission to create or modify workflows could achieve global prototype pollution via an unvalidated pagination parameter, potentially leading to remote code execution on the instance.

What happened

The n8n npm package is under investigation for a vulnerability that could allow authenticated users with permission to create or modify workflows to achieve global prototype pollution. This is reportedly done via an unvalidated pagination parameter, which could potentially lead to remote code execution on the instance. The affected versions are n8n (npm) <1.123.43, <2.20.7, and <2.22.1.

To mitigate this vulnerability, it is recommended to upgrade to n8n version 1.123.43, 2.20.7, or 2.22.1 or later. If an immediate upgrade is not possible, limiting workflow creation and editing permissions and disabling the HTTP Request node is advised. For more detailed information, consult the primary sources.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If n8n is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats