Expression Sandbox Bypass in n8n by n8n-io
CVE-2026-85165

7.2HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85165?

n8n versions prior to 2.36.2 are susceptible to a significant vulnerability that allows authenticated users with workflow-edit permissions to bypass the expression sandbox. This occurs when free identifiers are utilized in spread, computed-key, switch-case, or class-extension contexts, which inadvertently resolve to process globals. As a result, users can manipulate host objects through expression evaluations, leading to persistent changes across the process until the next restart. This poses a risk to the integrity and security of workflows within n8n, making it essential to upgrade to the latest version to mitigate potential exploits.

Affected Version(s)

n8n 0 < 2.36.2

n8n 0 < 2.35.4

n8n 2.36.2

References

CVSS V4

Score:
7.2
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

th3-j0k3r
.