Impact
n8n’s JavaScript executor used a single module cache for all users’ Code nodes. In affected releases prior to versions 1.123.67, 2.31.5, and 2.32.1, an attacker who could run a Code node could poison that cache and thereby influence the execution of Code nodes for other users on the same instance. The flaw does not provide sandbox escape or remote code execution directly, but it can compromise the confidentiality, integrity, or availability of other users’ workflows.
Affected Systems
The vulnerability impacts installations of the n8n automation platform before version 1.123.67 for the 1.x branch and before 2.31.5 and 2.32.1 for the 2.x branch. Only deployments that run the JavaScript task runner with built‑in or external modules enabled in a multi‑user edition are affected.
Risk and Exploitability
The CVSS score is 5.8, indicating a moderate level of severity. Exploit probability information (EPSS) is currently unavailable and the issue is not listed in the CISA KEV catalog. Attackers must be able to execute a Code node in a shared multi‑user instance; no external attacker can trigger the flaw from the network. Once compromised, the attacker can subvert the behavior of Code nodes for other users, potentially causing malicious code execution, unauthorized data disclosure, or disruption of workflows. The risk is confined to the instance’s users and does not extend beyond the application layer.
OpenCVE Enrichment