Code Injection in n8n - #VU146789

 

Code Injection in n8n - #VU146789

Published: September 2, 2026


Vulnerability identifier: #VU146789
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of code generation in the legacy expression engine when processing expressions that tamper with the global JSON.stringify value and inject code into generated source. A remote user can supply a crafted expression to execute arbitrary code.

Only instances running the legacy expression engine are vulnerable. The default vm expression engine is not affected.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.76, 2.37.7, 2.38.2

External References

Related Security Bulletins