n8n Node.js Package < 1.123.32 / 2.x < 2.17.4 / 2.18.x < 2.18.1 XML Node Prototype Pollution RCE (GHSA-hqr4-h3xv-9m3r)

critical Nessus Plugin ID 311438

Version 1.2

May 7, 2026, 8:04 AM

  • CVSS metrics ("CVSSv3 score" set to 8.8)
  • CVSS metrics ("CVSSv3 vector" set to "CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H")

Plugin Feed: 202605070804

Version 1.1

May 2, 2026, 1:15 AM

  • New

Plugin Feed: 202605020115

* Changelogs are generally available for changes made after Nov 1, 2022