Executive brief
n8n is a workflow automation platform used to orchestrate business processes and integrations. A vulnerability in the default legacy expression evaluator allows authenticated users with workflow creation or modification permissions to bypass security controls and execute arbitrary code with the privileges of the n8n process, potentially compromising the entire server and any data it accesses.
Technical details
The legacy expression evaluator in n8n contains a sanitizer bypass vulnerability in the computed-member handler that can be exploited by authenticated users. An attacker with workflow create or modify permissions can craft a malicious expression that bypasses the sanitizer validation, leading to arbitrary code execution at the host level with the privileges of the n8n process. Attack requires network access and valid authentication, but no user interaction. The vulnerability is fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users can temporarily mitigate by switching to the non-legacy expression engine (vm) via the N8N_EXPRESSION_ENGINE environment variable.
Affected products
- n8n n8n < 1.123.64, < 2.29.8, < 2.30.1
Timeline
- 2026-07-08: disclosed
- 2026-07-08: patched: Fixed in versions 1.123.64, 2.29.8, and 2.30.1
- 2026-07-22: advisory