n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
ID: db7ecdbd-33f3-54dd-a0d4-8f0a62a0a2a9
STIX ID: report--db7ecdbd-33f3-54dd-a0d4-8f0a62a0a2a9
Feed Name: CosmicBytez Labs
Threat Score
**n8n sandbox escape (GHSA-gv7g-jm28-cr3m, CVSS 8.7):** A high-severity sandbox-escape vulnerability was found in n8n that allows authenticated users with workflow edit rights to obtain a reference to Node.js globals and use Reflect.get to load child_process, enabling arbitrary OS command execution as the n8n process. Patched in 2.31.5 and 2.32.1; self-hosted instances must update, audit workflows, monitor child processes, rotate credentials, and restrict editor access.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
