SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-65591

HIGH · CVSS 8.8 EPSS 0.47% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A vulnerability exists in n8n's legacy expression evaluator, allowing authenticated users with workflow creation or modification permissions to bypass the sanitizer and execute arbitrary code at the host level. This poses a significant risk to systems running affected versions, as it can lead to complete compromise of the n8n process. Organizations using n8n should prioritize upgrading to versions 1.123.64, 2.29.8, or 2.30.1 to mitigate this high-severity threat.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65591
Severity
HIGH
CVSS
8.8
EPSS
0.47%

Original NVD Description

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

Related CVEs

Other vulnerabilities affecting the same vendor(s)