PoC Archive PoC Archive

tag

Node-Options

  • CVE-2026-44789 / GHSA-c8xv-5998-g76h web CRITICAL 9.4

    n8n HTTP Request Node Pagination Prototype Pollution → Remote Code Execution (CVE-2026-44789)

    The n8n HTTP Request node's pagination feature (updateAParameterInEachRequest mode) allows an attacker-controlled parameter.type value of proto, causing paginationData.request[parameter.type][parameterName] = parameterValue to write directly onto…

    Patched 2026-07-05
  • None assigned as of 2026-07-03 web HIGH

    Flowise Custom MCP Environment Variable Case Bypass

    Flowise's Custom MCP stdio node validates configured environment variables against a denylist (PATH, LDLIBRARYPATH, DYLDLIBRARYPATH, NODEOPTIONS) using exact, case-sensitive string comparison. Windows, however, treats environment variable names…

    Unverified 2026-07-03