What is CVE-2026-65591?
CVE-2026-65591 is a sanitizer bypass vulnerability in the computed-member handler of n8n's legacy expression evaluator. It allows an authenticated user with workflow permissions to execute host-level code by crafting a malicious expression. Users should immediately upgrade to the latest n8n version.
Azərbaycanca: CVE-2026-65591 n8n platformasının köhnə expression evaluator-un computed-member handler-ində sanitizer bypass zəifliyidir. Bu zəiflik autentifikasiya olunmuş istifadəçiyə xüsusi hazırlanmış ifadə ilə sanitizer-i keçərək n8n prosesi səviyyəsində əmr icra etməyə imkan verir. n8n administratorları dərhal ən son versiyaya yeniləmə aparmalıdır.
Related CVEs
link basis: same weakness class CWE-94; shared vendor: n8n
FAQ2
In which component of n8n does the CVE-2026-65591 vulnerability exist?
The CVE-2026-65591 vulnerability exists in the computed-member handler of n8n's legacy expression evaluator.
What level of access does an attacker need to exploit CVE-2026-65591?
The attacker needs to be an authenticated user.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.