Junglewise Threat Intelligence

CVE-2026-72765: n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission t

CVE-2026-72765 · Severity: critical · CVSS 9.9 · Published 2026-08-11

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that allows users to build and execute automated processes. An authenticated user with workflow creation or modification permissions can exploit arrow function expressions to bypass the security sandbox and execute arbitrary system commands on the host server, compromising the entire system.

Technical details

This is a sandbox escape vulnerability in n8n's expression evaluation engine (CWE-94: Code Injection). The root cause is improper validation of arrow function bodies in expressions, allowing an attacker to break out of the intended sandbox context. An authenticated user with workflow creation/modification permissions can craft malicious expressions using arrow functions to gain unauthenticated remote code execution on the underlying host. The attack requires authentication and workflow edit permissions but no user interaction. The vulnerability has been patched in n8n versions 2.31.5 and 2.32.1.

Affected products

  • n8n n8n all versions before 2.31.5 and 2.32.1

Timeline

  • 2026-07-22: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-gv7g-jm28-cr3m
  • 2026-07-22: patched: Fixed in n8n 2.31.5 and 2.32.1

References

Related threats