Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
8.7

CVE-2026-72765: n8n versions before 2.32.1 allow hackers to run system commands

CVE-2026-72765 · published 24 days ago
Summary

An attacker with permission to edit workflows in n8n can potentially run system commands on the server, which could lead to unauthorized access or data loss. This issue has been fixed in versions 2.31.5 and 2.32.1. It's recommended to update to one of these fixed versions to prevent potential security risks.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
n8n-io n8n < 2.32.1
< 2.31.5
n8n n8n >= 2.31.0, < 2.31.5
>= 2.32.0, < 2.32.1
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Original advisory text
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using ...
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.
Severity
8.7 High
Exploitation
EPSS <1%
Type
CWE-94Code Injection
Timeline
Published11 Aug 2026
Updated2 Sep 2026
First seen11 Aug 2026
Sources
CVE-2026-72765 · MITRE
Monitor software like this
Free during beta