Improper access control in n8n - #VU139105
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute system commands.
The vulnerability exists due to improper access control in the expression sandbox when evaluating crafted expressions with arrow-function bodies. A remote user can create or modify a workflow containing a crafted expression to execute system commands.
Exploitation requires permission to create or modify workflows.