ShellCodeX
Tools • Events • News • Insights
ShellCodeX Intelligence Brief
CRITICAL Vulnerabilities

n8n patches workflow expression sandbox escape enabling OS command execution

Source headline: n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

Threat level Critical
Signal strength 80/100
Source confidence 1 source
Published 2 hours ago

Intelligence Summary

n8n fixed a high-severity sandbox escape affecting its workflow expression handling. The issue could allow authenticated workflow editors to run operating-system commands on the host running n8n. Researchers discovered the bypass while testing the February fix for CVE-2026-27577. The problem impacts versions in the range 2.32.0 up to, but not including, 2.32.1. Users should update to the patched versions, including 2.31.5 and later releases that contain the fix, to reduce the risk of server compromise.

Recommended Action

Prioritize immediate review, validate exposure, and patch or mitigate affected systems.

Topics

#cve #sandbox-escape #expression-sandbox #n8n #os-command-execution #workflow-editors
Original reporting The Hacker News n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
Open original source