Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.stringify and cause later generated source to contain executable attacker-controlled code. The affected code-generation paths include packages/@n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts and packages/@n8n/tournament/src/ExpressionBuilder.ts, and the issue does not affect the vm expression engine. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 7.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Code Execution
Action: Patch Immediately
AI Analysis

Impact

n8n’s legacy expression engine builds source code by calling the mutable global JSON.stringify function. The vulnerability allows an attacker to replace JSON.stringify within an expression so that subsequent code generation includes attacker‑controlled code. The likely attack vector is crafting or modifying a workflow expression that performs this tampering, which then triggers execution of the injected code when the expression engine evaluates the generated source, giving the attacker full code‑execution privileges inside the n8n process.

Affected Systems

Versions of n8n prior to 1.123.76, 2.37.7, and 2.38.2 are affected. The flaw resides in the legacy expression engine used by packages/@n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts and packages/@n8n/tournament/src/ExpressionBuilder.ts. The vm expression engine is not impacted, and the vulnerability does not affect n8n releases newer than the listed versions.

Risk and Exploitability

The CVSS score of 7.7 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no documented widespread exploitation. The likely attack vector requires that an attacker can create or modify a workflow containing a malicious expression; once evaluated, the injected code runs with the permissions of the n8n worker process.

Generated by OpenCVE AI on September 9, 2026 at 09:11 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to the latest patched release (at least 1.123.76 for the 1.x line, 2.37.7 or 2.38.2 for the 2.x line).
  • If immediate upgrade is not possible, disable or restrict the legacy expression engine for regular users, preventing the replacement of global objects such as JSON.stringify.
  • Configure the workflow environment to use the vm expression engine, which is immune to this issue, and ensure that no custom code can bypass this restriction.

Generated by OpenCVE AI on September 9, 2026 at 09:11 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-6xcw-7xm6-48c6 n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
History

Fri, 11 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.stringify and cause later generated source to contain executable attacker-controlled code. The affected code-generation paths include packages/@n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts and packages/@n8n/tournament/src/ExpressionBuilder.ts, and the issue does not affect the vm expression engine. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
Weaknesses CWE-94
References
Metrics cvssV4_0

{'score': 7.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:24:59.627Z

Reserved: 2026-09-04T19:34:03.101Z

Link: CVE-2026-86083

cve-icon Vulnrichment

Updated: 2026-09-09T13:24:55.359Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.383

Modified: 2026-09-11T16:12:56.010

Link: CVE-2026-86083

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:10Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')