LOWVulnerability
Global

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

·Source: The Hacker News

Updated:

Executive Summary

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are =2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

Analysis

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are =2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

Indicators of Compromise (1)

CVE (1)
CVE-2026-27577
Source Attribution

Originally published by The Hacker News on Jul 27, 2026.

Related Threats