CRITICALVulnerability

CVE-2026-85165

n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.

Properties

severity
CRITICAL
score
9.9
epss_score
0.00315
cve_id
CVE-2026-85165
signal_observed_at
2026-09-15T21:12:51+00:00
vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
published_at
2026-09-03T13:06:23.710
last_modified
2026-09-10T19:55:37.867
epss_percentile
0.24273

Related Entities (4)

ENRICHED_BY (1)

[Source]FIRST EPSS

AFFECTS_PRODUCT (1)

[Product]

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-85165 — Ninja Signal Threat Intelligence | Ninja Signal