⚠ Withdrawn by GitHub Security Advisories

Withdrawn: July 22, 2026

GHSA-m7jc-p4hf-xhwqHighDisclosed before NVD

Duplicate Advisory: Legacy Expression Evaluator Sanitizer Bypass Leads to Authenticated Code Execution

Published
July 22, 2026
Last Modified
July 22, 2026

📋 Description

Duplicate Advisory

This advisory has been withdrawn because it is a duplicate of GHSA-pm35-fqvh-cq5g. This link is maintained to preserve external references.

Original Description

n8n contains a sanitizer bypass vulnerability in the legacy expression evaluator's computed-member handler. An authenticated user with workflow create or modify permissions can craft a malicious expression to bypass the sanitizer and achieve host-level code execution as the n8n process. The legacy expression engine is the default in affected versions. Fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

🎯 Affected products1

  • npm/n8n:< 1.123.64

🔗 References (4)