Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1. | |
| Title | n8n before 2.32.1 Remote Code Execution via Expression Sandbox Escape | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-94 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T17:50:33.952Z
Reserved: 2026-08-10T15:06:16.417Z
Link: CVE-2026-72765
Updated: 2026-08-11T17:44:23.392Z
Status : Received
Published: 2026-08-11T13:19:06.670
Modified: 2026-08-11T18:18:24.623
Link: CVE-2026-72765
No data.
OpenCVE Enrichment
No data.