THREAT OPS › Threat News › [GHSA] GHSA-hw8v-xxg5-vvvx (high) — n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
[GHSA] GHSA-hw8v-xxg5-vvvx (high) — n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
GHSA-hw8v-xxg5-vvvx Severity: high CVE: CVE-2026-86076
n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution
## Impact
The expression compiler's sanitizer resolved through a dynamically-scoped `this`, so a class field named `__sanitize` rebound it and reached the `Function` constructor. On the backend, any expression author could run code in the n8n proce
MITRE ATT&CK techniques
- JavaScriptT1059.007
Indicators of compromise
- CVE-2026-86076cve
Original source: https://github.com/advisories/GHSA-hw8v-xxg5-vvvx