ShellCodeX Intelligence Brief
CRITICAL
Vulnerabilities
n8n patches workflow expression sandbox escape enabling OS command execution
Source headline: n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
Threat level
Critical
Signal strength
80/100
Source confidence
1 source
Published
2 hours ago
Intelligence Summary
n8n fixed a high-severity sandbox escape affecting its workflow expression handling. The issue could allow authenticated workflow editors to run operating-system commands on the host running n8n. Researchers discovered the bypass while testing the February fix for CVE-2026-27577. The problem impacts versions in the range 2.32.0 up to, but not including, 2.32.1. Users should update to the patched versions, including 2.31.5 and later releases that contain the fix, to reduce the risk of server compromise.
Recommended Action
Prioritize immediate review, validate exposure, and patch or mitigate affected systems.
Topics
Original reporting
The Hacker News
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
Open original source