CVE-2026-65591CWE-917

n8n before 1.123.64 Sanitizer Bypass Remote Code Execution

High · published July 22, 2026

CVSS v4.0
8.9
EPSS
0%
Percentile
39.8
In the wild
Unconfirmed
What it is

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

The record
Technical detail
CVSS v4.0
8.9 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:L
EPSS
0.00481 · 39.8th percentile
Weakness
CWE-917 · Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
Published
2026-07-22T11:21Z
EPSS history
Timeline
  • 22 JUL 11:21Z
    n8n before 1.123.64 Sanitizer Bypass Remote Code Execution
    cvelistv5