PatchSiren cyber security CVE debrief
CVE-2026-72765 n8n-io CVE debrief
The CVE-2026-72765 vulnerability is a sandbox escape issue in n8n versions before 2.31.5 and 2.32.1. An authenticated user with workflow creation or modification permissions can craft expressions using arrow-function bodies to bypass the expression sandbox, leading to system command execution on the host. This issue has a high severity with a CVSS score of 8.7. The vulnerability is addressed in versions 2.31.5 and 2.32.1. Users of affected n8n versions, especially those with workflow creation or modification permissions, should be aware of this vulnerability and take steps to patch their instances. Administrators and security teams responsible for monitoring and securing workflow systems should also be informed to ensure proper mitigation and protection measures are in place.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-08-31
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-08-31
Who should care
Users of n8n versions before 2.31.5 and 2.32.1, especially those with workflow creation or modification permissions, should be aware of this vulnerability and take steps to patch their instances. Additionally, administrators and security teams responsible for monitoring and securing workflow systems should be informed about this issue to ensure proper mitigation and protection measures are in place.
Technical summary
The CVE-2026-72765 vulnerability affects n8n versions before 2.31.5 and 2.32.1. It allows an authenticated user with workflow creation or modification permissions to craft expressions using arrow-function bodies, bypassing the expression sandbox and triggering system command execution on the host. The CVSS score for this vulnerability is 8.7, indicating a high severity. The issue is fixed in versions 2.31.5 and 2.32.1.
Defensive priority
Authenticated users with workflow creation or modification permissions should prioritize patching n8n instances to version 2.31.5 or 2.32.1.
Recommended defensive actions
- Patch n8n instances to version 2.31.5 or 2.32.1
- Restrict workflow creation and modification permissions to trusted users
- Monitor n8n instance logs for suspicious activity
- Consider implementing additional security controls for workflow execution
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE-2026-72765 issue involves a sandbox escape vulnerability in expression evaluation within n8n versions before 2.31.5 and 2.32.1. An authenticated user with permission to create or modify workflows can exploit this by crafting expressions using arrow-function bodies, leading to system command execution on the host. The issue is addressed in versions 2.31.5 and 2.32.1. Evidence is based on official CVE and NVD records, as well as advisories from the vendor and Vulncheck.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72765 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72765
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72765 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72765
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/security/advisories/GHSA-gv7g-jm28-cr3m
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-expression-sandbox-escape
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.