n8n Patches Two Critical Flaws in One Day
On October 5, 2026, n8n disclosed two vulnerabilities: an expression sandbox escape CVE-2026-86076 (CVSS 8.7) and an argument injection CVE-2026-44790 (CVSS 9.4). Both grant an attacker full control of the server; fixes ship in versions 1.123.76, 2.37.7 and 2.38.2.
- CVE-2026-86076 (CVSS 8.7) escapes the expression sandbox via a __sanitize class field
- CVE-2026-44790 (CVSS 9.4) is an argument injection flaw (CWE-88)
- Fixed in n8n 1.123.76, 2.37.7 and 2.38.2
- No known exploitation in the wild so far
Read next
Security