Module Cache Poisoning Vulnerability in n8n by n8n.io
CVE-2026-72764
5.8MEDIUM
What is CVE-2026-72764?
The vulnerability arises from a design flaw in n8n's JavaScript task runner, where a single module cache is employed for all user Code-node executions. In versions prior to 1.123.67, 2.31.5, and 2.32.1, this flaw enables an attacker to manipulate the cached module, impacting the execution of other users' Code nodes. Such manipulation presents risks to confidentiality and integrity within shared multi-user environments, highlighting a critical need for updates when utilizing built-in or external modules.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
