PT-2026-70166 · N8N · N8N

·

CVE-2026-72764

·

Published

2026-07-22

·

Updated

2026-08-11

CVSS v4.0

5.8

Medium

VectorAV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions prior to 2.31.5 n8n versions prior to 2.32.1
Description The JavaScript task runner shares a single module cache across all users' Code-node executions. In multi-user instances where the JS task runner has built-in or external modules enabled, a user can poison a cached module. This allows the attacker to alter the executions of other users on the same runner, compromising confidentiality, integrity, or availability. This issue represents a cross-user isolation break within a single instance and is not a sandbox escape or remote code execution.
Recommendations Update to version 1.123.67 or later. Update to version 2.31.5 or later. Update to version 2.32.1 or later.

Exploit

Fix

RCE

Exposure of Resource to Wrong Sphere

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72764
GHSA-9CMH-XCQM-5HQR

Affected Products

N8N