n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
Overview
n8n, an automation platform, has addressed a serious security vulnerability that could allow authenticated users to execute operating system commands on the server. This flaw was discovered by Security Joes during their investigation of a previous fix related to CVE-2026-27577. The vulnerability affects versions 2.32.0 and earlier, specifically those prior to 2.32.1. The situation is critical as it could enable potential attackers to gain unauthorized access and control over the server, posing significant risks to any organization using n8n for their automation needs. Users are strongly urged to update to the patched versions to mitigate these risks.
Key Takeaways
- Affected Systems: n8n automation platform, versions =2.32.0,<2.32.1
- Action Required: Users should update to n8n versions 2.
- Timeline: Newly disclosed
Original Article Summary
n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are =2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and
Impact
n8n automation platform, versions =2.32.0,<2.32.1
Exploitation Status
No active exploitation has been reported at this time. However, organizations should still apply patches promptly as proof-of-concept code may exist.
Timeline
Newly disclosed
Remediation
Users should update to n8n versions 2.31.5 or later to address the vulnerability.
Additional Information
This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.
Related Topics: This incident relates to CVE, Vulnerability, Update, and 1 more.