CVE-2026-86076: n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution

Published Sep 8, 2026
·
Updated

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the expression compiler sanitizer resolved through dynamically scoped this and did not reject reserved class member names. A class field named sanitize could rebind the sanitizer and reach the Function constructor, enabling backend code execution and editor-preview JavaScript execution. The affected AST hook is PrototypeSanitizer in packages/workflow/src/expression-sandboxing.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.

Affected Software

1 affected component
n8n n8n<1.123.76, <=2.37.7, <=2.38.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 1.123.76
  2. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.37.7
  3. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.38.2
  4. Compensating control

    Apply compensating controls for stored cross-user JavaScript execution in the editor UI (e.g., restrict editor access/permissions to trusted users) while upgrading, since the affected AST hook is PrototypeSanitizer in packages/workflow/src/expression-sandboxing.ts.

Event History

Sep 8, 2026
CVE Published
via MITRE·09:28 PM
Data Sourced
via MITRE·09:28 PM
DescriptionWeakness

Frequently Asked Questions

1

Which n8n versions need to be updated?

Versions earlier than 1.123.76, 2.37.7, and 2.38.2 are affected. Upgrade to the applicable fixed version for your release line.

2

What capabilities could exploitation provide?

A crafted expression can escape the expression compiler sanitizer by rebinding it through a class field named __sanitize and reaching the Function constructor. This can enable backend code execution and JavaScript execution in editor previews for other users.

3

What component should be reviewed when assessing exposure?

The affected sanitizer hook is PrototypeSanitizer in packages/workflow/src/expression-sandboxing.ts. Environments using the vulnerable expression compiler behavior should be considered exposed until updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203