Junglewise Threat Intelligence

CVE-2026-77075: n8n expression injection in resource-locator field

CVE-2026-77075 · Severity: high · CVSS 7.3 · Published 2026-08-20

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform used to connect and orchestrate business applications and data sources. A flaw in how the editor renders resource-locator fields allows an authenticated user to inject malicious code that executes in another user's browser session when they open an affected workflow. This enables stealing session data, modifying workflows, or executing commands with the victim's privileges.

Technical details

The vulnerability is an expression injection (CWE-94) in the resource-locator field link preview rendering. The editor directly splices the field's stored value into the node type's URL template without sanitizing or validating for expression syntax. An authenticated member can craft a malicious field value containing n8n expressions; when another user opens the affected node in the editor, the expression is evaluated as JavaScript in the victim's authenticated session. This requires the attacker to be an authenticated member and the victim to open the malicious node, but results in arbitrary code execution in the victim's context. Patches are available in n8n 1.123.69, 2.33.4, and 2.34.1.

Affected products

  • n8n n8n before 1.123.69, 2.x before 2.33.4, 2.34.x before 2.34.1

Timeline

  • 2026-08-20: disclosed: Vulnerability disclosed via NVD and GitHub Security Advisory
  • 2026-08-05: patched: Patches available in versions 1.123.69, 2.33.4, and 2.34.1

References

Related threats