Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
News n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
The Hacker News
2 weeks ago

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

By info@thehackernews.com (The Hacker News)

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and

More from The Hacker News

Leaving Threaticon

This link opens an external site that isn't part of the platform.