Executive brief
n8n is a workflow automation platform that allows users to build and execute automated business processes. A sandbox bypass vulnerability allows authenticated users with workflow-edit permissions to execute arbitrary code through expression evaluation, potentially compromising the integrity and availability of the entire n8n instance. Attackers can persistently mutate shared system objects across all workflows until the process restarts, affecting all users and workflows on the same instance.
Technical details
This vulnerability exists in n8n's expression sandbox, which fails to properly rewrite free identifiers appearing in spread, computed-key, switch-case, and class-extension positions. Consequently, these identifiers resolve against process globals instead of being sandboxed, exposing over thirty host globals. An authenticated attacker with workflow-edit permission can craft malicious expressions that mutate these shared objects through expression evaluation. The changes persist process-wide across all subsequent expression evaluations until the n8n process is restarted. The vulnerability is classified as eval injection (CWE-95) and requires only low privilege (workflow-edit) and no user interaction, making it exploitable via network access.
Affected products
- n8n n8n < 2.36.2, < 2.35.4
Timeline
- 2026-08-19: disclosed: GitHub Security Advisory GHSA-fg85-4wv2-p98j published
- 2026-09-03: advisory: CVE-2026-85165 published on NVD