n8n-io/n8n · error · ExpressionError
Cannot access this property in a jmespath query due to…
Error message
Cannot access this property in a jmespath query due to security concerns
What it means
The jmespath wrapper scanned the query string for unsafe property tokens (constructor, __proto__, prototype-pollution vectors) and found one. Queries are treated as untrusted input; the throw prevents the query engine from traversing to object internals even when the data itself is clean.
Solutions
- Remove constructor/__proto__/prototype references from the JMESPath query
- Rewrite the query to select ordinary data properties only
- If the intent was type introspection, do it in a Code node instead of a jmespath expression
Defensive patterns
Strategy: validation
When it happens
Trigger: Thrown at packages/@n8n/expression-runtime/src/runtime/jmespath.ts:75 when the library encounters an invalid state.
Common situations: See trigger scenarios.
AI-assisted analysis of n8n-io/n8n@5ac6606e81 (2026-08-12).
Data as JSON: /api/errors/a335a9120a07c831.
Report an issue: GitHub.
Appendix: source
Thrown at packages/@n8n/expression-runtime/src/runtime/jmespath.ts:75
* would cost one synchronous host roundtrip per top-level key
* before the query even runs.
*
* Note on lazy proxies: when `data` is a lazy proxy (e.g. `$json`), each
* property access during `jmespath.search` triggers a synchronous host
* roundtrip via `getValueAtPath`. Functional but slow for deep traversals.
* Performance optimisation (e.g. bulk pre-fetch of the queried subtree) is
* a follow-up.
*/
export function jmesPath(data: unknown, query: string): unknown {
if (typeof data !== 'object' || typeof query !== 'string') {
throw new ExpressionError('expected two arguments (Object, string) for this function');
}
// jmespath decodes escape sequences inside quoted identifiers, so the
// token check must run against an unescaped query. Reject any backslash
// up front to keep the property-name match meaningful.
if (query.includes('\\') || unsafeJmespathPropertyPattern.test(query)) {
throw new ExpressionError(
'Cannot access this property in a jmespath query due to security concerns',
);
}
return jmespath.search(data as never, query);
}
View on GitHub (pinned to 5ac6606e81)