Impact
The vulnerability is a sandbox escape that allows a malicious user to define a special class field named __sanitize inside a workflow expression. Because the sanitizer did not reject reserved class member names and was invoked with a dynamically scoped this, an attacker could rebind the sanitizer to the Function constructor, causing arbitrary JavaScript code to be executed on the server and in the editor preview. This effectively grants the attacker full code execution on machines running n8n, enabling data exfiltration, privilege escalation, and service disruption.
Affected Systems
n8n, the open source workflow automation platform by n8n‑io. All installations of n8n with a version older than 1.123.76, 2.37.7, or 2.38.2 are vulnerable. The flaw resides in the expression compiler module in packages/workflow/src/expression-sandboxing.ts.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. Though no EPSS score is presently available and the issue is not listed in the CISA KEV catalog, the description suggests the likely attack vector involves exploitation through the web UI by an authenticated user capable of creating or editing expressions. Because the flaw is deep in the backend sanitizer, an attacker would need some level of authenticated access or privileged user rights to inject the malicious class field. The potential for remote code execution means any compromise could lead to full system compromise, warranting prompt mitigation.
OpenCVE Enrichment
Github GHSA