What is CVE-2026-72749?
CVE-2026-72749 is a prototype pollution vulnerability in the n8n platform's 'Edit Fields (Set)' node. It allows an authenticated user to manipulate an inherited built-in method path by naming a field with a specific dot-notation path, due to missing restrictions on field names. Updating to n8n versions 1.123.67, 2.31.5, or 2.32.1 is recommended.
Azərbaycanca: CVE-2026-72749, n8n platformunda 'Edit Fields (Set)' node-da aşkarlanmış prototype pollution zəifliyidir. Bu, autentifikasiya olunmuş istifadəçiyə xüsusi adlandırılmış sahə vasitəsilə built-in metod yolunu manipulyasiya etməyə imkan verir. n8n-i 1.123.67, 2.31.5 və ya 2.32.1 versiyalarına yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: n8n
FAQ2
In which component of n8n was CVE-2026-72749 discovered?
The vulnerability was discovered in the 'Edit Fields (Set)' node of the n8n platform.
To which n8n versions should one upgrade to protect against CVE-2026-72749?
It is recommended to update n8n to versions 1.123.67, 2.31.5, or 2.32.1.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.