Impact
n8n’s legacy expression engine builds source code by calling the mutable global JSON.stringify function. The vulnerability allows an attacker to replace JSON.stringify within an expression so that subsequent code generation includes attacker‑controlled code. The likely attack vector is crafting or modifying a workflow expression that performs this tampering, which then triggers execution of the injected code when the expression engine evaluates the generated source, giving the attacker full code‑execution privileges inside the n8n process.
Affected Systems
Versions of n8n prior to 1.123.76, 2.37.7, and 2.38.2 are affected. The flaw resides in the legacy expression engine used by packages/@n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts and packages/@n8n/tournament/src/ExpressionBuilder.ts. The vm expression engine is not impacted, and the vulnerability does not affect n8n releases newer than the listed versions.
Risk and Exploitability
The CVSS score of 7.7 indicates high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting no documented widespread exploitation. The likely attack vector requires that an attacker can create or modify a workflow containing a malicious expression; once evaluated, the injected code runs with the permissions of the n8n worker process.
OpenCVE Enrichment
Github GHSA