Sandbox Escape Vulnerability in n8n Workflow Automation Tool
CVE-2026-72765
8.7HIGH
What is CVE-2026-72765?
n8n, a popular workflow automation tool, is susceptible to a sandbox escape vulnerability in its expression evaluation feature. An authenticated user with the ability to create or modify workflows can exploit this vulnerability by crafting expressions that utilize arrow-function bodies. This allows them to bypass the expression sandbox, potentially enabling system command execution on the host that runs n8n. The issue has been resolved in versions 2.31.5 and 2.32.1, emphasizing the importance of updating to these versions to maintain security.
Affected Version(s)
n8n 0 < 2.32.1
n8n 0 < 2.31.5
n8n 2.32.1
