Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. n8n
  4. ›
  5. CVE-2026-86083

CVE-2026-86083: n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

September 10, 2026

Two stages of expression code generation built source text by calling the global JSON.stringify at generation time: the compiler when printing synthetic string literals, and the isolate bridge when interpolating a timezone value into its per-evaluation wrapper. An expression that replaced that global therefore changed the code that was subsequently generated and executed, turning literal data into executable source. The patch renders both code-generation stages through a reference captured at module load, so a later change to global state cannot alter the generated source.

This vulnerability only affects instances running the legacy expression engine. The vm expression engine, which is the default on the patched releases, is not affected.

References

  • github.com/advisories/GHSA-6xcw-7xm6-48c6
  • github.com/n8n-io/n8n/releases/tag/n8n@1.123.76
  • github.com/n8n-io/n8n/releases/tag/n8n@2.37.7
  • github.com/n8n-io/n8n/releases/tag/n8n@2.38.2
  • github.com/n8n-io/n8n/security/advisories/GHSA-6xcw-7xm6-48c6
  • nvd.nist.gov/vuln/detail/CVE-2026-86083

Code Behaviors & Features

Detect and mitigate CVE-2026-86083 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 1.123.76, all versions starting from 2.0.0 before 2.37.7, all versions starting from 2.38.0 before 2.38.2

Fixed versions

  • 1.123.76
  • 2.37.7
  • 2.38.2

Solution

Upgrade to versions 1.123.76, 2.37.7, 2.38.2 or above.

Impact 8.8 HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-94: Improper Control of Generation of Code ('Code Injection')

Source file

npm/n8n/CVE-2026-86083.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Tue, 22 Sep 2026 12:19:39 +0000.