n8n HTTP Request Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain
cve · CVE-2026-42232
Coverage
2
first 2026-05-19 → last 2026-05-19
Latest activity
2026-05-19
n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform…
Peak priority
high
1 high · 1 notable
Targets
public-sector
sectors: public-sector, technology, education · regions: europe
Sources cited
10
3 hosts
Defender insights
What each entry about CVE-2026-42232 tells a defender to do, newest first.
Detection
Story timeline
- 2026-05-19n8n prototype-pollution chain (CVE-2026-42231 et al.): authenticated-to-RCE on a workflow-automation platform that Swiss/EU agencies increasingly stand up as their integration bus
- 2026-05-19CVE-2026-42231 / -42232 / -44789 / -44790 / -44791, n8n self-hosted automation: chained prototype-pollution and injection flaws enabling authenticated-to-RCE plus a Git-node arbitrary file read
Hunting pivots
ATT&CK techniques (5 across 3 tactics)
5 techniques observed across 1 entry about this entity, derived from entry metadata and body evidence, never asserted without a published entry behind it · pinned to MITRE ATT&CK v19.2 · compare on the matrix · Navigator layer (JSON)
- Initial AccessExploit Public-Facing Application
- ExecutionCommand and Scripting Interpreter · Command and Scripting Interpreter: JavaScript
- Privilege EscalationExploitation for Privilege Escalation · Escape to Host
Initial Access TA0001
T1190Exploit Public-Facing Application×1
Adversaries may attempt to exploit a weakness in an Internet-facing host or system to initially access a network. The weakness in the system can be a software bug, a temporary glitch, or a misconfiguration.
Evidence: 2026-05-19/n8n-prototype-pollution-chain-cve-2026-42231-et-al-authentic · ATT&CK page ↗
Execution TA0002
T1059Command and Scripting Interpreter×1
Adversaries may abuse command and script interpreters to execute commands, scripts, or binaries. These interfaces and languages provide ways of interacting with computer systems and are a common feature across many different platforms. Most systems come with some built-in command-line interface and scripting capabilities, for example, macOS and Linux distributions include some flavor of Unix Shell while Windows installations include the Windows Command Shell and PowerShell.
Evidence: 2026-05-19/n8n-prototype-pollution-chain-cve-2026-42231-et-al-authentic · ATT&CK page ↗
T1059.007Command and Scripting Interpreter: JavaScript×1
Adversaries may abuse various implementations of JavaScript for execution. JavaScript (JS) is a platform-independent scripting language (compiled just-in-time at runtime) commonly associated with scripts in webpages, though JS can be executed in runtime environments outside the browser.
Evidence: 2026-05-19/n8n-prototype-pollution-chain-cve-2026-42231-et-al-authentic · ATT&CK page ↗
Privilege Escalation TA0004
T1068Exploitation for Privilege Escalation×1
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges. Exploitation of a software vulnerability occurs when an adversary takes advantage of a programming error in a program, service, or within the operating system software or kernel itself to execute adversary-controlled code. Security constructs such as permission levels will often hinder access to information and use of certain techniques, so adversaries will likely need to perform privilege escalation to include use of software exploitation to circumvent those restrictions.
Evidence: 2026-05-19/n8n-prototype-pollution-chain-cve-2026-42231-et-al-authentic · ATT&CK page ↗
T1611Escape to Host×1
Adversaries may break out of a container or virtualized environment to gain access to the underlying host. This can allow an adversary access to other containerized or virtualized resources from the host level or to the host itself. In principle, containerized / virtualized resources should provide a clear separation of application functionality and be isolated from the host environment.
Evidence: 2026-05-19/n8n-prototype-pollution-chain-cve-2026-42231-et-al-authentic · ATT&CK page ↗
Entries about n8n HTTP Request Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain (2)
Co-occurring entities
Derived: referenced by the same focused operational entries (weekly summaries and report roundups don't count); ×N counts the shared entries.
- n8n Git node SSH chain, terminal sink of CVE-2026-42231 prototype-pollution to RCE×2
- n8n self-hosted automation, xml2js prototype pollution (CWE-1321), root of authenticated-to-RCE chain via Git node SSH×2
- n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain×2
- n8n XML Node injection, companion amplifier to CVE-2026-42231 prototype-pollution chain×2
Where this entity is cited
Source distribution
- github.com5 (50%)
- attack.mitre.org4 (40%)
- thehackernews.com1 (10%)
External references
All cited sources (10)
- github.comprimaryn8n GHSA-57g9-58c2-xjg3https://github.com/n8n-io/n8n/security/advisories/GHSA-57g9-58c2-xjg3
- github.comprimaryn8n GHSA-c8xv-5998-g76hhttps://github.com/n8n-io/n8n/security/advisories/GHSA-c8xv-5998-g76h
- github.comprimaryn8n GHSA-hqr4-h3xv-9m3rhttps://github.com/n8n-io/n8n/security/advisories/GHSA-hqr4-h3xv-9m3r
- github.comprimaryn8n GHSA-q5f4-99jv-pgg5https://github.com/n8n-io/n8n/security/advisories/GHSA-q5f4-99jv-pgg5
- github.comprimaryn8n GHSA-wrwr-h859-xh2rhttps://github.com/n8n-io/n8n/security/advisories/GHSA-wrwr-h859-xh2r
- attack.mitre.orgT1059.007 Command and Scripting Interpreter: JavaScripthttps://attack.mitre.org/techniques/T1059/007/
- attack.mitre.orgT1068 Exploitation for Privilege Escalationhttps://attack.mitre.org/techniques/T1068/
- attack.mitre.orgT1190 Exploit Public-Facing Applicationhttps://attack.mitre.org/techniques/T1190/
- attack.mitre.orgT1611 Escape to Hosthttps://attack.mitre.org/techniques/T1611/
- thehackernews.comThe Hacker Newshttps://thehackernews.com/2026/05/ivanti-fortinet-sap-vmware-n8n-patch.html