CVE-2026-44789 is a prototype-pollution vulnerability in the n8n HTTP Request node. An unvalidated pagination parameter allows an authenticated user who can create or modify workflows to manipulate JavaScript object prototypes globally. The flaw affects n8n releases prior to 1.123.43, 2.20.7, and 2.22.1, as applicable to the deployed release branch. When chained with other techniques, the prototype pollution may enable remote code execution on the n8n instance.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
n8n-nodes-base.httpRequest to the NODES_EXCLUDE environment variable. These measures reduce exposure but do not fully eliminate the risk.Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a compact end-to-end proof-of-concept exploit for CVE-2026-44789 affecting n8n. It is not framework-based; the main artifact is exploit.py, supported by documentation (README.md, ANALYSIS.md, EVIDENCE.txt) and a lab environment definition (lab/docker-compose.yml). The exploit targets authenticated users who can create or modify workflows on vulnerable n8n versions and turns a prototype pollution bug in the HTTP Request node pagination logic into host-level command execution. Core exploit capability: exploit.py authenticates to the n8n REST API, creates three workflows, and triggers them in sequence. The first workflow writes a malicious JavaScript file to disk using Set -> Convert to File -> Read/Write Files nodes. The second workflow abuses the vulnerable HTTP Request pagination mode updateAParameterInEachRequest by setting parameter type to __proto__ and name to NODE_OPTIONS, causing Object.prototype.NODE_OPTIONS to be set globally in the main n8n process. The third workflow uses a Code node containing while(true){} to hang the task runner so it is killed and respawned. On respawn, Node.js inherits the polluted NODE_OPTIONS through environment enumeration and loads the attacker’s file with --require, yielding arbitrary command execution. The exploit uses only Python standard library modules (argparse, json, sys, time, urllib) and interacts with the target over HTTP endpoints under /rest and /webhook. It is operational rather than weaponized: it provides a working payload and full chain automation, but payload customization is basic and hardcoded around writing a JS file and executing a supplied shell command. The included docker-compose lab pins n8nio/n8n:1.123.42, exposes port 5678, enables runners, and lowers N8N_RUNNERS_TASK_TIMEOUT to make the respawn easier to observe. Repository structure: README.md explains the vulnerability, affected/fixed versions, exploit chain, and reproduction steps; ANALYSIS.md gives code-level reasoning for the sink and gadget; EVIDENCE.txt records a successful run and resulting command output; exploit.py is the executable PoC; lab/docker-compose.yml provides a reproducible vulnerable environment. Overall purpose: demonstrate and automate a verified authenticated prototype-pollution-to-RCE chain against vulnerable n8n deployments.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.