GHSA-9cmh-xcqm-5hqr: n8n: Cross-Tenant Module-Cache Poisoning in the JS Task Runner
n8n’s JavaScript task runner shared one module cache across all users’ Code-node executions, so a user able to run a Code node could poison a cached module and alter other users’ Code-node executions on the same runner, affecting their confidentiality, integrity, or availability.
This is a cross-user isolation break within a single n8n instance. It does not constitute a sandbox escape or remote code execution. All multi-user n8n instances running the JS task runner with built-in or external modules enabled are affected.
References
Code Behaviors & Features
Detect and mitigate GHSA-9cmh-xcqm-5hqr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →