← Back to Feed
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
CVE-2026-27577
July 27, 2026 · The Hacker News · Severity: HIGH
n8n patched a high-severity expression-sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m, CVSS 8.7) that lets authenticated workflow editors execute OS commands on the n8n server. Security Joes discovered the flaw while probing n8n's February fix for CVE-2026-27577 for bypasses. Affected versions are =2.32.0,<2.32.1. The exploit requires a valid account with workflow creation or modification permissions but no victim interaction.
Key Takeaways
- n8n expression-sandbox escape (CVSS 8.7) lets authenticated workflow editors execute OS commands on the server.
- Security Joes found the bypass while testing the previous February 2026 sandbox escape fix.
- Exploitation requires a valid account with workflow editing permissions but no user interaction.