PT-2026-70166 · N8N · N8N
CVSS v4.0
5.8
Medium
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.67
n8n versions prior to 2.31.5
n8n versions prior to 2.32.1
Description
The JavaScript task runner shares a single module cache across all users' Code-node executions. In multi-user instances where the JS task runner has built-in or external modules enabled, a user can poison a cached module. This allows the attacker to alter the executions of other users on the same runner, compromising confidentiality, integrity, or availability. This issue represents a cross-user isolation break within a single instance and is not a sandbox escape or remote code execution.
Recommendations
Update to version 1.123.67 or later.
Update to version 2.31.5 or later.
Update to version 2.32.1 or later.
Exploit
Fix
RCE
Exposure of Resource to Wrong Sphere
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
N8N