Module Cache Poisoning Vulnerability in n8n by n8n.io
CVE-2026-72764

5.8MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72764?

The vulnerability arises from a design flaw in n8n's JavaScript task runner, where a single module cache is employed for all user Code-node executions. In versions prior to 1.123.67, 2.31.5, and 2.32.1, this flaw enables an attacker to manipulate the cached module, impacting the execution of other users' Code nodes. Such manipulation presents risks to confidentiality and integrity within shared multi-user environments, highlighting a critical need for updates when utilizing built-in or external modules.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

thesecguy45
.