n8n versions before 2.36.2 contain an expression sandbox...
High severity
Unreviewed
Published
Sep 3, 2026
to the GitHub Advisory Database
•
Updated Sep 3, 2026
Description
Published by the National Vulnerability Database
Sep 3, 2026
Published to the GitHub Advisory Database
Sep 3, 2026
Last updated
Sep 3, 2026
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.
References