PT-2026-63349 · N8N · N8N
CVSS v4.0
8.9
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.64
n8n versions prior to 2.29.8
n8n versions prior to 2.30.1
Description
A sanitizer bypass exists in the legacy expression evaluator's computed-member handler. An authenticated user with permissions to create or modify workflows can craft a malicious expression to bypass the sanitizer, leading to host-level code execution with the privileges of the n8n process. The legacy expression engine is the default in the affected versions.
Recommendations
Update to version 1.123.64 or later.
Update to version 2.29.8 or later.
Update to version 2.30.1 or later.
Switch to the non-legacy expression engine by setting
N8N EXPRESSION ENGINE=vm.
Restrict instance access to fully trusted users only.Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N