N8N · N8N · CVE-2026-72765
**Name of the Vulnerable Software and Affected Versions**
n8n versions prior to 2.31.5
n8n versions prior to 2.32.1
**Description**
A sandbox escape exists during expression evaluation. An authenticated user with permissions to create or modify workflows can use arrow-function bodies to bypass the expression sandbox, allowing the execution of system commands on the host machine.
**Recommendations**
Update to version 2.31.5 or later.
Update to version 2.32.1 or later.