CyberRota Analysis
AI-GeneratedVersions of n8n prior to 2.36.2 are vulnerable to an expression sandbox bypass that allows authenticated users with workflow-edit permissions to manipulate host objects through expression evaluation, affecting process globals. This could lead to unauthorized modifications that persist across sessions, posing a significant risk to system integrity. Organizations using n8n should prioritize upgrading to the latest version to mitigate this high-severity vulnerability.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.
Related CVEs
Other vulnerabilities affecting the same vendor(s)