CVE-2026-33696 | n8n-io n8n up to 1.123.26/2.13.2/2.14.0 Parameter NODES_EXCLUDE prototype pollution (GHSA-mxrg-77hm-89hv / EUVD-2026-15945)
A vulnerability classified as critical has been found in n8n-io n8n up to 1.123.26/2.13.2/2.14.0. This affects an unknown function of the component Parameter Handler. This manipulation of the argument NODES_EXCLUDE causes improperly controlled modification of object prototype attributes.
This vulnerability is tracked as CVE-2026-33696. The attack is possible to be carried out remotely. No exploit exists.
It is recommended to upgrade the affected component.