n8n-io/n8n · error · Error

Object.getPrototypeOf is not allowed

Error message

Object.getPrototypeOf is not allowed

What it means

The safe-globals Object proxy blocks getPrototypeOf by throwing (unlike reflection methods, which are merely undefined). Prototype walking is a standard sandbox-escape and prototype-pollution primitive, so expression code attempting Object.getPrototypeOf is rejected outright as a security violation.

Solutions

  1. Remove Object.getPrototypeOf (and Object.setPrototypeOf/`__proto__` access) from the expression
  2. Use structural checks (typeof, Array.isArray, instanceof where available) instead of prototype inspection
  3. Do metaprogramming in a Code node, not in an inline expression
Defensive patterns

Strategy: validation

When it happens

Trigger: Thrown at packages/@n8n/expression-runtime/src/runtime/safe-globals.ts:34 when the library encounters an invalid state.

Common situations: See trigger scenarios.


AI-assisted analysis of n8n-io/n8n@5ac6606e81 (2026-08-12). Data as JSON: /api/errors/2594fcead9a7c5b8. Report an issue: GitHub.

Appendix: source

Thrown at packages/@n8n/expression-runtime/src/runtime/safe-globals.ts:34

		const blockedMethods = [
			'defineProperty',
			'defineProperties',
			'setPrototypeOf',
			'getOwnPropertyDescriptor',
			'getOwnPropertyDescriptors',
			'__defineGetter__',
			'__defineSetter__',
			'__lookupGetter__',
			'__lookupSetter__',
		];

		if (blockedMethods.includes(prop as string)) {
			return undefined;
		}

		// Block getPrototypeOf by throwing (more secure than returning undefined)
		if (prop === 'getPrototypeOf') {
			throw new Error('Object.getPrototypeOf is not allowed');
		}

		// Wrap Object.create to accept only one argument (blocks property descriptor injection)
		if (prop === 'create') {
			return (proto: object | null) => Object.create(proto);
		}

		// Allow other Object methods
		const value = (target as any)[prop];
		if (typeof value === 'function') {
			// Use arrow function wrapper to preserve 'this' binding
			return (...args: any[]) => value.apply(target, args);
		}
		return value;
	},
});

/**

View on GitHub (pinned to 5ac6606e81)