CVE-2026-85165CWE-95

CVE-2026-85165

published September 3, 2026

CVSS
7.2
EPSS
0%
Percentile
17.3
In the wild
Unconfirmed
What it is

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.

The record
Technical detail
CVSS
7.2 · NONE
CVSS v4.0
7.2 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00258 · 17.3th percentile
Weakness
CWE-95 · Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')
Published
2026-09-03T17:06Z
References (2)
EPSS history
Timeline
  • 05 SEP 03:44Z
    EPSS moved — → 0%
    epss
  • 03 SEP 11:22Z
    n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement
    cvelistv5