Security · 1h ago
n8n Patches Sandbox Escape Allowing OS Command Execution
n8n fixed a high-severity sandbox escape vulnerability that let authenticated workflow editors run OS commands on the server. Security Joes discovered the flaw while testing a previous patch for CVE-2026-27577. The fix is in versions 2.31.5 and 2.32.1.
Meridian48 take
The bypass of a previous patch underscores how tricky sandbox escapes are to fully seal in automation platforms.
Read the full reporting
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process →
The Hacker News
n8nsandbox-escape