Executive brief
n8n is a workflow automation platform that allows users to build and execute automated processes. A vulnerability in its JavaScript task runner allows one user to poison a shared module cache, enabling them to alter other users' code executions and potentially access their data or disrupt their workflows. This breaks user isolation within multi-user instances where multiple teams or organizations share the same n8n deployment.
Technical details
The JavaScript task runner in n8n maintains a single shared module cache across all users executing Code nodes, enabling a module-cache poisoning attack. A user with code execution privileges (which is common in n8n's multi-user setup) can inject malicious code into cached modules, affecting subsequent Code-node executions by other users on the same runner. The vulnerability is triggered when built-in or external modules are enabled via NODE_FUNCTION_ALLOW_BUILTIN or NODE_FUNCTION_ALLOW_EXTERNAL environment variables. An authenticated user with Code node execution capability can exploit this; no additional user interaction is required. The impact is cross-user isolation break affecting confidentiality, integrity, and availability of other users' workflows. Patches are available in n8n versions 1.123.67, 2.31.5, and 2.32.1.
Affected products
- n8n n8n < 1.123.67, 2.0.0-rc.0 to < 2.31.5, 2.32.0
Timeline
- 2026-07-22: disclosed: Vulnerability published via GHSA-9cmh-xcqm-5hqr
- 2026-07-22: patched: Patches released in n8n 1.123.67, 2.31.5, and 2.32.1