Aller au contenu

Fiche vulnérabilité

CVE-2026-65591 : faille élevée n8n n8n (CVSS 8.8)

Description

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

En bref

Sévérité
Élevée (CVSS 8.8)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
22 juil. 2026
Dernière mise à jour
27 juil. 2026

Produits concernés

  • n8n n8n

Références

Rechercher une autre vulnérabilité dans la base CVE