CVE Tools

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

The Hacker NewsBy The Hacker News

Patchn8n

Our summary

n8n has addressed a high-severity sandbox escape vulnerability that could allow authenticated users to execute arbitrary OS commands on the server hosting the automation platform. The flaw, tracked as GHSA-gv7g-jm28-cr3m, affects versions less than 2.31.5 and between 2.32.0 and 2.32.1. Security Joes discovered the issue while testing for potential bypasses of an earlier fix for CVE-2026-27577. The vulnerability allows attackers with workflow editing permissions to run commands under the privileges of the n8n process. Administrators are advised to upgrade to either version 2.31.5 or 2.32.1 immediately.

Read at The Hacker News

The Hacker News publishes this story on its own site; we link to it rather than reprint it.

Worried this affects your company?

Discuss a security assessment of your internet-facing systems. Scope agreed before testing.

Check my exposure

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store