n8n-io/n8n · error · ExpressionError
Cannot access " " due to security concerns
Error message
Cannot access "${key}" due to security concerns What it means
Sentinel error code carried by RuntimeError when expression evaluation inside the V8 isolate exceeded the memory ceiling. The bridge (evaluator.ts) translates this code to MemoryLimitError for the host — the throw site is the runtime's resource monitor, and the fault is an expression allocating too much (huge arrays, deep spreads, unbounded string building).
Solutions
- Simplify the expression: avoid spreading large arrays ($json spread, deep Object.assign chains)
- Move heavy data shaping into a Code node, which runs outside the isolate limits
- Reduce the input data size (filter rows earlier in the workflow, avoid whole-dataset mapping in expressions)
- Chunk the work across multiple nodes instead of one monolithic expression
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/@n8n/expression-runtime/src/runtime/safe-globals.ts:157 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of n8n-io/n8n@5ac6606e81 (2026-08-12).
Data as JSON: /api/errors/0192a90bb4e3060f.
Report an issue: GitHub.
Appendix: source
Thrown at packages/@n8n/expression-runtime/src/runtime/safe-globals.ts:157
'__defineGetter__',
'__defineSetter__',
'__lookupGetter__',
'__lookupSetter__',
'toString',
'valueOf',
'toLocaleString',
'hasOwnProperty',
'isPrototypeOf',
'propertyIsEnumerable',
]);
export function __sanitize(value: unknown): unknown {
// Symbols are not string-coercible and fall outside the denylist; pass through.
if (typeof value === 'symbol') return value;
// Coerce once and return the string so the caller uses the already-checked key.
const key = String(value);
if (unsafeObjectProperties.has(key)) {
throw new ExpressionError(`Cannot access "${key}" due to security concerns`);
}
return key;
}
View on GitHub (pinned to 5ac6606e81)