n8n-io/n8n · error

Dangerous column header

Error message

Dangerous column header "${header.trim()}" found in ${format} data

What it means

Guard in parseCsvTsv that rejects CSV/TSV input whose header row contains a key in the DANGEROUS_KEYS set (prototype-pollution keys like __proto__, constructor, prototype). It fires after header extraction and before any rows are returned, mirroring the equivalent JSON validation, because such headers would become object keys downstream.

Solutions

  1. Rename or remove the dangerous column header from the source file before parsing
  2. If the header is legitimate data, load the file with hasHeader disabled or preprocess it outside the tool
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/@n8n/instance-ai/src/parsers/structured-file-parser.ts:306 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of n8n-io/n8n@5ac6606e81 (2026-08-12). Data as JSON: /api/errors/118cb8ca918ef2f1. Report an issue: GitHub.

Appendix: source

Thrown at packages/@n8n/instance-ai/src/parsers/structured-file-parser.ts:306

		return { rawHeaders: [], allRows: [] };
	}

	let rawHeaders: string[];
	let dataRows: string[][];

	if (options.hasHeader) {
		rawHeaders = records[0];
		dataRows = records.slice(1);
	} else {
		const colCount = records[0].length;
		rawHeaders = Array.from({ length: colCount }, (_, i) => `column_${i}`);
		dataRows = records;
	}

	// Check for dangerous keys in CSV/TSV headers (consistent with JSON validation)
	for (const header of rawHeaders) {
		if (DANGEROUS_KEYS.has(header.trim())) {
			throw new Error(`Dangerous column header "${header.trim()}" found in ${format} data`);
		}
	}

	return { rawHeaders, allRows: dataRows };
}

function parseJson(content: string): {
	rawHeaders: string[];
	allRows: Array<Record<string, unknown>>;
} {
	let parsed: unknown;
	try {
		parsed = JSON.parse(content);
	} catch {
		throw new Error('Invalid JSON: failed to parse');
	}

	if (!Array.isArray(parsed)) {

View on GitHub (pinned to 5ac6606e81)