THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-hw8v-xxg5-vvvx (high) — n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

[GHSA] GHSA-hw8v-xxg5-vvvx (high) — n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

medgithub_advisoriesPublished 2026-09-10

GHSA-hw8v-xxg5-vvvx Severity: high CVE: CVE-2026-86076

n8n: Expression Sandbox Escape via Class-Field Sanitizer Rebinding Can Lead to Code Execution

## Impact

The expression compiler's sanitizer resolved through a dynamically-scoped `this`, so a class field named `__sanitize` rebound it and reached the `Function` constructor. On the backend, any expression author could run code in the n8n proce

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-hw8v-xxg5-vvvx