CRITICALVulnerability

CVE-2026-72765

n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command execution on the host running n8n. The issue is fixed in versions 2.31.5 and 2.32.1.

Properties

severity
CRITICAL
score
9.9
cve_id
CVE-2026-72765
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-08-11T13:19:06.670
last_modified
2026-09-01T20:19:04.077

Related Entities (4)

AFFECTS_PRODUCT (2)

[Product]
[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Control of Generation of Code ('Code Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72765 — Ninja Signal Threat Intelligence | Ninja Signal