Home ยท Wiki ยท Incidents & Campaigns
type: incident ยท created: 2026-07-28 ยท updated: 2026-07-28 ยท tags: [incident] ยท confidence: high ยท affected_sectors: [technology] ยท au_impact: false

n8n Patches Severity 8.7 expression-sandbox Escape Discovered by Security Joes

Summary

Automation platform n8n patched a high-severity expression-sandbox escape enabling authenticated workflow editors to execute arbitrary operating system commands.

Details

Automation platform n8n has patched a high-severity expression-sandbox escape vulnerability. The vulnerability is tracked as GHSA-gv7g-jm28-cr3m with a CVSS score of 8.7.

Vulnerability Mechanics

The escape allows authenticated workflow editors to bypass previous restrictions and execute arbitrary operating system commands on the host server. It was discovered by security firm Security Joes while investigating previous fixes for Cve 2026 27577 N8N Sandbox Escape.

Affected Versions and Remediation

The vulnerable ranges include: - Versions prior to 2.31.5 - Versions between 2.32.0 and 2.32.1 (excluding 2.32.1)

Fixes are now available in versions 2.31.5 and 2.32.1. Administrators are strongly urged to update immediately and should not rely on tentative user access controls.

Related Pages