GHSA-pm35-fqvh-cq5g
n8n: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution
Quick fix
GHSA-pm35-fqvh-cq5g — n8n: upgrade to the fixed version with the command below.
npm install n8n@1.123.64 Details
## Impact The legacy expression evaluator's computed-member sanitizer can be bypassed by an authenticated user with workflow create or modify permissions. Successful exploitation grants the attacker host-level code execution as the n8n process.
The legacy expression engine is the default engine in affected versions.
## Patches The issue has been fixed in n8n versions 1.123.64, 2.29.8, and 2.30.1. Users should upgrade to one of these versions or later to remediate the vulnerability.
## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Switch to the non-legacy expression engine by setting `N8N_EXPRESSION_ENGINE=vm`.
These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-pm35-fqvh-cq5g [WEB]
- https://nvd.nist.gov/vuln/detail/CVE-2026-65591 [ADVISORY]
- https://github.com/n8n-io/n8n [PACKAGE]
- https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.64 [WEB]
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.29.8 [WEB]
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.30.1 [WEB]
- https://www.vulncheck.com/advisories/n8n-before-sanitizer-bypass-remote-code-execution [WEB]