logo

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

ID: db7ecdbd-33f3-54dd-a0d4-8f0a62a0a2a9

STIX ID: report--db7ecdbd-33f3-54dd-a0d4-8f0a62a0a2a9

Feed Name: CosmicBytez Labs

Threat Score
78/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

...
...

**n8n sandbox escape (GHSA-gv7g-jm28-cr3m, CVSS 8.7):** A high-severity sandbox-escape vulnerability was found in n8n that allows authenticated users with workflow edit rights to obtain a reference to Node.js globals and use Reflect.get to load child_process, enabling arbitrary OS command execution as the n8n process. Patched in 2.31.5 and 2.32.1; self-hosted instances must update, audit workflows, monitor child processes, rotate credentials, and restrict editor access.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.