CVE-2026-54306: n8n
Medium severity, CVSS 6.4. EPSS: 0.3% chance of exploitation in the next 30 days.
n8n is an open source workflow automation platform. Prior to 2.25.7 and 2.26.2, a prototype pollution vulnerability allowed a crafted public webhook payload to inject attacker-controlled fields into workflow data during internal object copying. These fields could be surfaced and consumed as normal values by downstream built-in nodes. Where a workflow combines a public webhook with action nodes that consume the resulting fields, an attacker could cause the workflow to act as a confused deputy — targeting unintended records or issuing outbound requests using the workflow owner's configured credentials. This vulnerability is fixed in 2.25.7 and 2.26.2.
Affected products
- n8n n8n: before 2.25.7 (fixed in 2.25.7); from 2.26.0, before 2.26.2 (fixed in 2.26.2)
Published 2026-06-23. Last modified 2026-06-26.