n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
Patchn8nOur summary
n8n has addressed a high-severity sandbox escape vulnerability that could allow authenticated users to execute arbitrary OS commands on the server hosting the automation platform. The flaw, tracked as GHSA-gv7g-jm28-cr3m, affects versions less than 2.31.5 and between 2.32.0 and 2.32.1. Security Joes discovered the issue while testing for potential bypasses of an earlier fix for CVE-2026-27577. The vulnerability allows attackers with workflow editing permissions to run commands under the privileges of the n8n process. Administrators are advised to upgrade to either version 2.31.5 or 2.32.1 immediately.
The Hacker News publishes this story on its own site; we link to it rather than reprint it.
Worried this affects your company?
Discuss a security assessment of your internet-facing systems. Scope agreed before testing.