Executive brief
n8n is a popular workflow automation tool used to connect various business applications and services. A security flaw in its legacy expression engine allows an authorized user to bypass safety filters and execute unauthorized commands on the underlying server. This could lead to a complete takeover of the n8n instance, potentially exposing sensitive credentials and automated business data.
Technical details
A vulnerability exists in n8n's legacy expression evaluator where the computed-member sanitizer can be bypassed. This is classified as an Expression Language Injection (CWE-917). An authenticated attacker with permissions to create or modify workflows can craft a malicious expression that escapes the sandbox, leading to host-level code execution as the n8n process. The legacy engine is the default in affected versions. The issue is resolved in versions 1.123.64, 2.29.8, and 2.30.1. A temporary workaround involves switching the expression engine to 'vm' via environment variables.
Affected products
- n8n-io n8n < 1.123.64, >= 2.0.0-rc.0 < 2.29.8, >= 2.30.0 < 2.30.1
Timeline
- 2026-07-08: disclosed: Initial report by Junming Wu (Dremig)
- 2026-07-22: advisory: GitHub Advisory published