← Back to Feed

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

CVE-2026-27577

July 27, 2026 · The Hacker News · Severity: HIGH

n8n patched a high-severity expression-sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m, CVSS 8.7) that lets authenticated workflow editors execute OS commands on the n8n server. Security Joes discovered the flaw while probing n8n's February fix for CVE-2026-27577 for bypasses. Affected versions are =2.32.0,<2.32.1. The exploit requires a valid account with workflow creation or modification permissions but no victim interaction.

Key Takeaways

  • n8n expression-sandbox escape (CVSS 8.7) lets authenticated workflow editors execute OS commands on the server.
  • Security Joes found the bypass while testing the previous February 2026 sandbox escape fix.
  • Exploitation requires a valid account with workflow editing permissions but no user interaction.
☕ Buy a Coffee