Critical severity9.9NVD Advisory· Published Aug 11, 2026· Updated Sep 1, 2026
CVE-2026-72765
CVE-2026-72765
Description
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
2- github.com/n8n-io/n8n/security/advisories/GHSA-gv7g-jm28-cr3mnvdMitigationVendor Advisory
- www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-expression-sandbox-escapenvdThird Party Advisory
News mentions
1- N8n: 16 Vulnerabilities Including RCE and SQLi Disclosed in Single BatchVypr Intelligence · Aug 11, 2026