the.bay.news

CVE-2026-33696: From a Schema Name to RCE in n8n

Simon Koeck
CVE-2026-33696: From a Schema Name to RCE in n8n
n8n uses a user-supplied schema name as a bare object key. Set it to __proto__, pollute the prototype, chain into RCE via the Git node. One request, full shell.

0 comments

Sign in to join the discussion — your thebay.events account works here.

No comments yet.