CVE-2026-65591High▾ MidnightPoC availablen8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 41.3 · likelihood 0.1 · exploitation 12
A public proof-of-concept already exists for this vulnerability — see Exploit availability below.
Public exploit / PoC code seen in 1 source. Availability, not in-the-wild use.
Exploit-prediction probability, daily snapshots since Jul 23.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.5%
1 GitHub repo
The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permissions. Successful exploitation grants the attacker host-level code execution as the n8n process.
The legacy expression engine is the default engine in affected versions.
The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability.
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
N8N_EXPRESSION_ENGINE=vm.These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
n8n < 1.123.64n8n >= 2.30.0, < 2.30.1n8n >= 2.0.0-rc.0, < 2.29.8Upgrade to a patched release:
n8n 1.123.64n8n 2.30.1n8n 2.29.8Field changes observed since this record was first indexed.
Connected by shared product, vendor, weakness, or advisory.
GHSA-m7jc-p4hf-xhwqHighDuplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
CVE-2026-65596Mediumn8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
CVE-2026-65589Mediumn8n: Custom Header Credential Values Leaked in Plaintext into LLM Node Execution Data
CVE-2026-65593Mediumn8n: Authenticated SSRF via Dynamic Node Parameters Endpoints Allows Internal Network Access
CVE-2026-65016Highn8n: SSO Instance-Role Provisioning Allows Privilege Escalation to Instance Owner
CVE-2026-65598Highn8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution