DIRAS TAKE
Urgent: public exploit code exists, so apply the vendor fixes immediately or isolate instances that allow workflow creation/modification to reduce exposure.
What is CVE-2026-65591?
An authenticated user who can create or edit workflows can abuse a flaw in n8n’s older expression engine to craft expressions that evade sanitization and run commands on the host process, resulting in host-level remote code execution. Tracked as CVE-2026-65591, the issue affects n8n 1.x releases prior to 1.123.64 and 2.x releases prior to 2.29.8 or 2.30.1; those fixed releases close the vulnerability. Exploitation requires an account with workflow create or modify privileges; no additional user interaction is necessary beyond those rights.
Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Which versions of n8n-io n8n are affected?
| BRANCH | AFFECTED | FIXED |
|---|---|---|
| 1.x | before 1.123.64 | 1.123.64 |
| 2.x | before 2.30.1 | 2.30.1 |
| 2.x | before 2.29.8 | 2.29.8 |
Is CVE-2026-65591 being exploited?
Public exploit code is available.
How to fix CVE-2026-65591
- Upgrade n8n to one of the patched releases: 1.123.64, 2.29.8, or 2.30.1.
- Remove or tightly control accounts that have workflow create or modify permissions and rotate credentials as needed.
- Restrict access to n8n instances via network controls to trusted networks only.
- Monitor workflow activity and system logs for unexpected executions or commands and follow vendor guidance.
Frequently asked questions
Is CVE-2026-65591 being actively exploited?
Public exploit code is available for CVE-2026-65591, indicating a higher risk of active exploitation.
Which n8n versions are affected by CVE-2026-65591?
Affected versions are n8n 1.x before 1.123.64 and 2.x before 2.29.8 or 2.30.1; the legacy expression engine is the default in these releases.
Is there a patch for CVE-2026-65591?
Yes. The vulnerability is fixed in n8n 1.123.64, 2.29.8, and 2.30.1.
Does CVE-2026-65591 require authentication?
Yes. Exploitation requires an authenticated n8n account with permissions to create or modify workflows.
References
- nvd.nist.gov/vuln/detail/CVE-2026-65591
- cve.org/CVERecord?id=CVE-2026-65591
- github.com/n8n-io/n8n/security/advisories/GHSA-pm35-fqvh-cq5g
- vulncheck.com/advisories/n8n-before-sanitizer-bypass-remote-code-execution
- All n8n-io CVEs on CVE Radar
- CVEs published in September 2026