Skip to content

Build1 publisher2 min readPublished

n8n patches two server-takeover flaws rated CVSS 8.7 and 9.4 across three release lines

n8n disclosed two server-takeover flaws on October 5, rated CVSS 8.7 and 9.4, with fixes in versions 1.123.76, 2.37.7 and 2.38.2. On a shared instance, the 8.7-rated sandbox escape lets anyone who can edit a workflow run code on the server.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying n8n patches two server-takeover flaws rated CVSS 8.7 and 9.4 across three release lines
Generated illustration

What happened

  • CVE-2026-86076 lets a crafted workflow expression escape n8n's expression sandbox and run arbitrary code inside the n8n process.
  • In the editor preview, the same crafted expression runs JavaScript in the browser session of whoever opens the workflow.
  • CVE-2026-44790, the higher-scored of the pair, is an argument-injection flaw classified CWE-88, improper neutralization of argument delimiters.
  • Advisory metadata lists neither flaw as known to be exploited and says an attacker needs hands-on effort to exploit either one.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure On a shared instance that has not been patched, one malicious or compromised editor account can run code in the process that holds the credentials and execution history of every workflow.
  • decision Operators have to schedule the 9.4-rated fix on advisory metadata alone, because the published details are too thin to judge their own exposure to it.
  • constraint Deployments on 1.x have to take 1.123.76 and put off the move to 2.x, because its breaking changes make it a bad choice for an emergency upgrade.

An n8n expression is a snippet such as `={{ $json.name }}` inside a node parameter. It is evaluated when the workflow runs [6]. The sandbox around it lets the snippet transform data. It is also supposed to keep the snippet off the server, stop it spawning processes and block the JavaScript `Function` constructor [6]. According to a dev.to write-up of n8n's advisory GHSA-hw8v-xxg5-vvvx, the expression compiler resolved its sanitizer through a dynamically scoped `this` [7]. That meant an expression could redefine the sanitizer. An attacker could declare a class field named `__sanitize`, rebind the sanitizer to a malicious value and reach the `Function` constructor [7].

To exploit it, the attacker has to write an expression. The write-up counts anyone who can create or edit a workflow as an expression author [11]. On an instance with one operator, the only author is the operator. On a shared instance, every client, contractor and junior team member with edit rights is an author. The write-up says those deployments should treat the upgrade as urgent [11].

The patch rejects reserved class-member names such as `__sanitize` [10]. It is a small change that is easy to review. I want that in a fix shipped on three release lines at once [4].

CVE-2026-44790 is harder to plan around. It has the higher score and a critical rating [3]. According to the write-up, n8n has published fewer details about it than about the sandbox escape [12]. The write-up does not say which input reaches the injected arguments, or what access an attacker needs first. It recommends patching both flaws in the same window [17]. The advisory metadata says vendor patches were already shipping in the fixed lines, so one upgrade covers both flaws [16].

Do the upgrade steps in this order:

1. Export `N8N_ENCRYPTION_KEY` from the running container into a secrets manager. Stored credentials are encrypted with this key. If an upgrade fails and the key is gone, those credentials stay locked [13]. 2. Back up the data store, which is a SQLite file or a Postgres database [13]. For Docker with a named volume, the write-up stops the container, tars the volume through a throwaway alpine container and starts n8n again. An external Postgres database gets a `pg_dump` instead [15]. A volume backup without the key restores credentials nobody can decrypt [13]. 3. Pull the fixed build for the release line you already run in production [4][14].

What to watch

  • n8n or NVD publishing fuller details for CVE-2026-44790, including which input reaches the injected arguments and what access an attacker needs.
  • Any change to either advisory's not-known-to-be-exploited status, such as public proof-of-concept code.
  • A further advisory showing a different way to rebind the expression sanitizer that the reserved-name check does not block.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories