Improper privilege management in n8n - #VU140997

 

Improper privilege management in n8n - #VU140997

Published: August 5, 2026


Vulnerability identifier: #VU140997
CSH Severity: Low
CVSS v4: 7.2 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper access control in the JavaScript task runner sandbox when executing user-supplied Code node JavaScript. A remote user can pollute the EventEmitter prototype to execute arbitrary code.

In shared runner deployments, the polluted prototype persists across subsequent Code node executions scheduled on the same runner and can affect other tenants, but not the host.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.69, 2.33.4, 2.34.1

External References

Related Security Bulletins