THREAT OPS › Threat News › [GHSA] GHSA-6xcw-7xm6-48c6 (high) — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
[GHSA] GHSA-6xcw-7xm6-48c6 (high) — n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
GHSA-6xcw-7xm6-48c6 Severity: high CVE: CVE-2026-86083
n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
## Impact
Two stages of expression code generation built source text by calling the global `JSON.stringify` at generation time: the compiler when printing synthetic string literals, and the isolate bridge when interpolating a timez
Indicators of compromise
- CVE-2026-86083cve
Original source: https://github.com/advisories/GHSA-6xcw-7xm6-48c6