Sanitizer Bypass Vulnerability in n8n by n8n.io
CVE-2026-65591
8.9HIGH
What is CVE-2026-65591?
The n8n platform is vulnerable due to a critical issue in its legacy expression evaluator, where the computed-member handler does not adequately sanitize user inputs. This flaw enables authenticated users with permissions to create or modify workflows to construct malevolent expressions, leading to potential host-level code execution. It is essential for users of affected versions to upgrade to 1.123.64, 2.29.8, or 2.30.1 to mitigate this risk.
Affected Version(s)
n8n 0 < 1.123.64
n8n 0 < 2.30.1
n8n 0 < 2.29.8
