< BACK TO NEWS
importantSYS.SOURCE: The Hacker News2026-07-27T18:35:15+05:30

n8n Sandbox Escape Vulnerability Allows Execution of OS Commands by Workflow Editors

A high-severity sandbox escape vulnerability in n8n allows authenticated workflow editors to execute OS commands with the n8n process's privileges. The issue was patched in versions 2.31.5 and 2.32.1, with a CVSS score of 8.7 and no CVE assigned as of July 2026.

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass.

The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

Read original article

*** END OF TRANSMISSION ***