Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 03 Sep 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 03 Sep 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n versions before 2.36.2 contain an expression sandbox bypass vulnerability where free identifiers in spread, computed-key, switch-case, or class-extension positions resolve against process globals. Authenticated users with workflow-edit permission can mutate host objects through expression evaluation, with changes persisting process-wide until restart. | |
| Title | n8n before 2.36.2 Expression Sandbox Bypass via SpreadElement | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-95 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-03T12:22:07.824Z
Reserved: 2026-09-03T11:05:09.078Z
Link: CVE-2026-85165
Updated: 2026-09-03T12:22:00.823Z
Status : Received
Published: 2026-09-03T13:06:23.710
Modified: 2026-09-03T13:06:23.710
Link: CVE-2026-85165
No data.
OpenCVE Enrichment
Updated: 2026-09-03T15:30:05Z
-
CWE-95
Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')