Code Injection in n8n - #VU146804

 

Code Injection in n8n - #VU146804

Published: September 2, 2026


Vulnerability identifier: #VU146804
CSH Severity: Medium
CVSS v4: 8.7 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-94
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to execute arbitrary code.

The vulnerability exists due to improper control of dynamically managed code resources in the expression compiler sanitizer when processing expressions with a class field named __sanitize. A remote user can craft an expression that rebinds the sanitizer and reaches the Function constructor to execute arbitrary code.

On the backend, exploitation runs code in the n8n process. In the editor preview, a member\'s expression can run as JavaScript in the session of whoever opens the workflow.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.76, 2.37.7, 2.38.2

External References

Related Security Bulletins