type: incident ยท created: 2026-07-27 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท affected_sectors: [] ยท au_impact: false
n8n Sandbox Escape Lets Workflow Editors Run OS Commands (CVSS 8.7)
Summary
Security Joes discovered a high-severity expression-sandbox escape in the n8n automation platform (GHSA-gv7g-jm28-cr3m, CVSS 8.7) that allows authenticated workflow editors to execute operating-system commands on the n8n server.
Key Details
| Field | Detail |
|---|---|
| Advisory | GHSA-gv7g-jm28-cr3m |
| CVSS | 8.7 (High) |
| Product | n8n automation platform |
| Versions affected | <2.31.5, and >=2.32.0 <2.32.1 |
| Patched versions | 2.31.5, 2.32.1 |
| Prerequisites | Authenticated workflow editor role |
| Discovered by | Security Joes |
| CVE assigned | No (as of 2026-07-27) |
Context
The flaw was discovered while Security Joes researchers were probing the February 2026 fix for Cve 2026 27577 N8N Sandbox Escape, indicating the original patch was incomplete and a bypass remained exploitable for several months.
Mitigation
Administrators should upgrade to: - n8n 2.31.5 (for the 2.31.x line) - n8n 2.32.1 (for the 2.32.x line)
Related
- Cve 2026 27577 N8N Sandbox Escape|Cve 2026 27577 N8N Sandbox Escape โ Original n8n sandbox vulnerability (patched February 2026)