Home ยท Wiki ยท Vulnerabilities & CVEs
type: cve ยท created: 2026-07-28 ยท updated: 2026-08-18 ยท tags: [] ยท confidence: not-rated ยท severity: high ยท affected_sectors: [] ยท au_impact: false

CVE-2026-27577

Overview

CVE-2026-27577 is a vulnerability in the n8n automation platform that was patched in February 2026. The flaw relates to expression sandboxing in n8n's workflow execution engine.

Significance

This CVE gained renewed attention when researchers at Security Joes discovered a follow-on sandbox escape (GHSA-gv7g-jm28-cr3m, CVSS 8.7) while probing the February fix for CVE-2026-27577. The discovery indicates that the original patch was incomplete, and a subsequent bypass remained exploitable until versions 2.31.5 and 2.32.1 were released.

Timeline

Date Event
February 2026 Original CVE-2026-27577 patch released
2026-07-27 Security Joes discloses follow-on sandbox escape discovered while probing the February fix

Related

References