THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-6xcw-7xm6-48c6 (high) — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

[GHSA] GHSA-6xcw-7xm6-48c6 (high) — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

medgithub_advisoriesPublished 2026-09-10

GHSA-6xcw-7xm6-48c6 Severity: high CVE: CVE-2026-86083

n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution

## Impact

Two stages of expression code generation built source text by calling the global `JSON.stringify` at generation time: the compiler when printing synthetic string literals, and the isolate bridge when interpolating a timez

Indicators of compromise

Original source: https://github.com/advisories/GHSA-6xcw-7xm6-48c6