VDB

GCVE-110-NCSC-2026-248

GCVE-110-NCSC-2026-248
Advisory PublishedCVSS 9.0/10
Vulnetix · Advisory published July 17, 2026
A second-order expression injection vulnerability in n8n's Form nodes could allow unauthenticated attackers to inject and evaluate arbitrary expressions, potentially leading to remote code execution when combined with a sandbox escape, fixed in versions 2.10.1, 2.9.3, and 1.123.22.

Weaknesses (CWE)

CWE-94Improper Control of Generation of Code ('Code Injection')CWE-497Exposure of Sensitive System Information to an Unauthorized Control SphereCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-80Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS)CWE-290Authentication Bypass by Spoofing

Risk Scores

CVSS 3.1
9.0/10
Critical · CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Products

VendorProductVersionsPlatforms
n8nvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

76,019 records in the GCVE database · Updated August 5, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›