n8n Patches Severity 8.7 expression-sandbox Escape Discovered by Security Joes
Summary
Automation platform n8n patched a high-severity expression-sandbox escape enabling authenticated workflow editors to execute arbitrary operating system commands.
Details
Automation platform n8n has patched a high-severity expression-sandbox escape vulnerability. The vulnerability is tracked as GHSA-gv7g-jm28-cr3m with a CVSS score of 8.7.
Vulnerability Mechanics
The escape allows authenticated workflow editors to bypass previous restrictions and execute arbitrary operating system commands on the host server. It was discovered by security firm Security Joes while investigating previous fixes for Cve 2026 27577 N8N Sandbox Escape.
Affected Versions and Remediation
The vulnerable ranges include: - Versions prior to 2.31.5 - Versions between 2.32.0 and 2.32.1 (excluding 2.32.1)
Fixes are now available in versions 2.31.5 and 2.32.1. Administrators are strongly urged to update immediately and should not rely on tentative user access controls.
Related Pages
- N8N Sandbox Escape Lets Workflow Editors Run Os Commands Cvss 8 7 \n- Cve 2026 27577 N8N Sandbox Escape\n\nSources: raw/digests/Cyber-Digest-2026-07-28