Expression Sandbox Escape in n8n by n8n-io
CVE-2026-85169

8.7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
3 September 2026

What is CVE-2026-85169?

The n8n platform has a vulnerability due to an expression sandbox escape in the $fromAI handler. This issue affects versions prior to 1.123.73, 2.35.4, and 2.36.2. It allows attackers with workflow-build privileges to exploit the vulnerability by resolving a caller-supplied placeholder name, which can lead to access and execution of arbitrary code within the main n8n process through the prototype chain. This presents a serious threat, as it can potentially compromise the integrity and security of the affected system.

Affected Version(s)

n8n 0 < 1.123.73

n8n 0 < 2.36.2

n8n 0 < 2.35.4

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Haruna38
.