logo

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

ID: 01b25415-dda4-5571-8c6d-465765121d16

STIX ID: report--01b25415-dda4-5571-8c6d-465765121d16

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2026-07-27

Date Updated: 2026-07-27

Author: [email protected] (The Hacker News)

...
...

n8n patched a high-severity expression-sandbox escape (tracked as GHSA-gv7g-jm28-cr3m, CVSS 8.7) that could let an authenticated workflow editor execute OS commands on the host, exposing the N8N_ENCRYPTION_KEY, stored credentials, and access to internal services; affected ranges were <2.31.5 and >=2.32.0,<2.32.1 with fixes in 2.31.5 and 2.32.1, and defenders are advised to update, review workflows for suspicious arrow functions or obfuscated JS, hunt for spawned shells, and rotate credentials where suspicious activity is found.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.