• PoC PUBLIC
  • PATCH AVAILABLE

CVE-2026-65591: authenticated remote code execution in n8n-io n8n

An authenticated user who can create or edit workflows can abuse a flaw in n8n’s older expression engine to craft expressions that evade sanitization and run commands on the host process, resulting in host-level remote code execution. Tracked as CVE-2026-65591, the issue affects n8n 1.x releases prior to 1.123.64 and 2.x releases prior to 2.29.8 or 2.30.1; those fixed releases close the vulnerability. Exploitation requires an account with workflow create or modify privileges; no additional user interaction is necessary beyond those rights.

Published Updated Source: CVE Program, NVD, FIRST EPSS, Vendor advisory

CVSS 3.1
8.8HIGH
EPSS
0.00694
CWE
CWE-917
KEV DUE DATE
Not listed
PATCH
Available

DIRAS TAKE

Urgent: public exploit code exists, so apply the vendor fixes immediately or isolate instances that allow workflow creation/modification to reduce exposure.

What is CVE-2026-65591?

An authenticated user who can create or edit workflows can abuse a flaw in n8n’s older expression engine to craft expressions that evade sanitization and run commands on the host process, resulting in host-level remote code execution. Tracked as CVE-2026-65591, the issue affects n8n 1.x releases prior to 1.123.64 and 2.x releases prior to 2.29.8 or 2.30.1; those fixed releases close the vulnerability. Exploitation requires an account with workflow create or modify privileges; no additional user interaction is necessary beyond those rights.

Vector CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Which versions of n8n-io n8n are affected?

BRANCHAFFECTEDFIXED
1.xbefore 1.123.641.123.64
2.xbefore 2.30.12.30.1
2.xbefore 2.29.82.29.8

Is CVE-2026-65591 being exploited?

Public exploit code is available.

How to fix CVE-2026-65591

  1. Upgrade n8n to one of the patched releases: 1.123.64, 2.29.8, or 2.30.1.
  2. Remove or tightly control accounts that have workflow create or modify permissions and rotate credentials as needed.
  3. Restrict access to n8n instances via network controls to trusted networks only.
  4. Monitor workflow activity and system logs for unexpected executions or commands and follow vendor guidance.

Frequently asked questions

Is CVE-2026-65591 being actively exploited?

Public exploit code is available for CVE-2026-65591, indicating a higher risk of active exploitation.

Which n8n versions are affected by CVE-2026-65591?

Affected versions are n8n 1.x before 1.123.64 and 2.x before 2.29.8 or 2.30.1; the legacy expression engine is the default in these releases.

Is there a patch for CVE-2026-65591?

Yes. The vulnerability is fixed in n8n 1.123.64, 2.29.8, and 2.30.1.

Does CVE-2026-65591 require authentication?

Yes. Exploitation requires an authenticated n8n account with permissions to create or modify workflows.

References