Build1 publisher2 min readPublished
n8n patches two server-takeover flaws rated CVSS 8.7 and 9.4 across three release lines
n8n disclosed two server-takeover flaws on October 5, rated CVSS 8.7 and 9.4, with fixes in versions 1.123.76, 2.37.7 and 2.38.2. On a shared instance, the 8.7-rated sandbox escape lets anyone who can edit a workflow run code on the server.
The Engineer · Build desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- CVE-2026-86076 lets a crafted workflow expression escape n8n's expression sandbox and run arbitrary code inside the n8n process.
- In the editor preview, the same crafted expression runs JavaScript in the browser session of whoever opens the workflow.
- CVE-2026-44790, the higher-scored of the pair, is an argument-injection flaw classified CWE-88, improper neutralization of argument delimiters.
- Advisory metadata lists neither flaw as known to be exploited and says an attacker needs hands-on effort to exploit either one.
Compiled by The EngineerSomething wrong?How this is made
Why it matters
- exposure On a shared instance that has not been patched, one malicious or compromised editor account can run code in the process that holds the credentials and execution history of every workflow.
- decision Operators have to schedule the 9.4-rated fix on advisory metadata alone, because the published details are too thin to judge their own exposure to it.
- constraint Deployments on 1.x have to take 1.123.76 and put off the move to 2.x, because its breaking changes make it a bad choice for an emergency upgrade.
An n8n expression is a snippet such as `={{ $json.name }}` inside a node parameter. It is evaluated when the workflow runs [6]. The sandbox around it lets the snippet transform data. It is also supposed to keep the snippet off the server, stop it spawning processes and block the JavaScript `Function` constructor [6]. According to a dev.to write-up of n8n's advisory GHSA-hw8v-xxg5-vvvx, the expression compiler resolved its sanitizer through a dynamically scoped `this` [7]. That meant an expression could redefine the sanitizer. An attacker could declare a class field named `__sanitize`, rebind the sanitizer to a malicious value and reach the `Function` constructor [7].
To exploit it, the attacker has to write an expression. The write-up counts anyone who can create or edit a workflow as an expression author [11]. On an instance with one operator, the only author is the operator. On a shared instance, every client, contractor and junior team member with edit rights is an author. The write-up says those deployments should treat the upgrade as urgent [11].
The patch rejects reserved class-member names such as `__sanitize` [10]. It is a small change that is easy to review. I want that in a fix shipped on three release lines at once [4].
CVE-2026-44790 is harder to plan around. It has the higher score and a critical rating [3]. According to the write-up, n8n has published fewer details about it than about the sandbox escape [12]. The write-up does not say which input reaches the injected arguments, or what access an attacker needs first. It recommends patching both flaws in the same window [17]. The advisory metadata says vendor patches were already shipping in the fixed lines, so one upgrade covers both flaws [16].
Do the upgrade steps in this order:
1. Export `N8N_ENCRYPTION_KEY` from the running container into a secrets manager. Stored credentials are encrypted with this key. If an upgrade fails and the key is gone, those credentials stay locked [13]. 2. Back up the data store, which is a SQLite file or a Postgres database [13]. For Docker with a named volume, the write-up stops the container, tars the volume through a throwaway alpine container and starts n8n again. An external Postgres database gets a `pg_dump` instead [15]. A volume backup without the key restores credentials nobody can decrypt [13]. 3. Pull the fixed build for the release line you already run in production [4][14].
What to watch
- n8n or NVD publishing fuller details for CVE-2026-44790, including which input reaches the injected arguments and what access an attacker needs.
- Any change to either advisory's not-known-to-be-exploited status, such as public proof-of-concept code.
- A further advisory showing a different way to rebind the expression sanitizer that the reserved-name check does not block.