CVE-2026-59206
Severity CVSS v4.0:
HIGH
Type:
Unavailable / Other
Publication date:
09/07/2026
Last modified:
09/07/2026
Description
n8n is an open source workflow automation platform. Prior to 1.123.61, 2.27.4, and, 2.28.1, an authenticated user with the default workflow:create permission could pollute Object.prototype through a crafted workflow saved, updated, or imported via the workflow API, allowing unauthenticated requests to be treated as a privileged user and exposing user and project listing endpoints. This issue is fixed in versions 1.123.61, 2.27.4, and 2.28.1.
Impact
Base Score 4.0
7.10
Severity 4.0
HIGH
Base Score 3.x
7.10
Severity 3.x
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | 1.123.61 (excluding) | |
| cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | 2.0.0 (including) | 2.27.4 (excluding) |
| cpe:2.3:a:n8n:n8n:2.28.0:*:*:*:*:node.js:*:* |
To consult the complete list of CPE names with products and versions, see this page



