Junglewise Threat Intelligence

CVE-2026-72764: n8n's JavaScript task runner shared a single module cache across all users' Code-node executions. In affected versions (before 1.123.67, 2.3

CVE-2026-72764 · Severity: high · CVSS 8.8 · Published 2026-08-11

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to build and execute automated processes. A vulnerability in its JavaScript task runner allows one user to poison a shared module cache, enabling them to alter other users' code executions and potentially access their data or disrupt their workflows. This breaks user isolation within multi-user instances where multiple teams or organizations share the same n8n deployment.

Technical details

The JavaScript task runner in n8n maintains a single shared module cache across all users executing Code nodes, enabling a module-cache poisoning attack. A user with code execution privileges (which is common in n8n's multi-user setup) can inject malicious code into cached modules, affecting subsequent Code-node executions by other users on the same runner. The vulnerability is triggered when built-in or external modules are enabled via NODE_FUNCTION_ALLOW_BUILTIN or NODE_FUNCTION_ALLOW_EXTERNAL environment variables. An authenticated user with Code node execution capability can exploit this; no additional user interaction is required. The impact is cross-user isolation break affecting confidentiality, integrity, and availability of other users' workflows. Patches are available in n8n versions 1.123.67, 2.31.5, and 2.32.1.

Affected products

  • n8n n8n < 1.123.67, 2.0.0-rc.0 to < 2.31.5, 2.32.0

Timeline

  • 2026-07-22: disclosed: Vulnerability published via GHSA-9cmh-xcqm-5hqr
  • 2026-07-22: patched: Patches released in n8n 1.123.67, 2.31.5, and 2.32.1

References

Related threats