CVE-2026-85165

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*

History

No history.

Information

Published : 2026-09-03 13:06

Updated : 2026-09-10 19:55


NVD link : CVE-2026-85165

Mitre link : CVE-2026-85165

CVE.ORG link : CVE-2026-85165


JSON object : View

Products Affected

n8n

  • n8n
CWE
CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')