CyberRota Analysis
AI-GeneratedA vulnerability exists in n8n's legacy expression evaluator, allowing authenticated users with workflow creation or modification permissions to bypass the sanitizer and execute arbitrary code at the host level. This poses a significant risk to systems running affected versions, as it can lead to complete compromise of the n8n process. Organizations using n8n should prioritize upgrading to versions 1.123.64, 2.29.8, or 2.30.1 to mitigate this high-severity threat.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)