Improper access control in n8n - #VU139109
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to cause a denial of service.
The vulnerability exists due to improper access control in the VM expression engine sandbox when creating or editing a workflow expression that uses array-element access. A remote user can obtain a reference to a host built-in and pollute its prototype to cause a denial of service.
Only instances running the VM expression engine are vulnerable.