Vulnerability Description
n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| N8N | N8N | < 2.35.4 |
Related Weaknesses (CWE)
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-fg85-4wv2-p98jMitigationVendor Advisory
- https://www.vulncheck.com/advisories/n8n-before-2.36.2-expression-sandbox-bypassThird Party Advisory
FAQ
What is CVE-2026-85165?
CVE-2026-85165 is a vulnerability with a CVSS score of 9.9 (CRITICAL). n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals....
How severe is CVE-2026-85165?
CVE-2026-85165 has been rated CRITICAL with a CVSS base score of 9.9/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2026-85165?
Check the references section above for vendor advisories and patch information. Affected products include: N8N N8N.