BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

n8n patches high-severity sandbox escape allowing OS command execution

n8n patches high-severity sandbox escape allowing authenticated workflow editors to execute OS commands.

  • n8n fixed a high-severity sandbox escape (CVSS 8.7) in versions 2.31.5 and 2.32.1 that could allow authenticated workflow editors to execute OS commands on the server.
  • Security Joes discovered the bypass while testing n8n’s February patch for CVE-2026-27577, exploiting an arrow-function gap and Reflect.get() to reach real Node.js globals.
  • Exploitation requires a valid account with workflow-edit permissions and may expose encryption keys, stored credentials, and connected internal services; no active exploitation has been reported yet.

n8n has patched a high-severity expression-sandbox escape that lets an authenticated workflow editor execute operating-system commands on the server running the automation platform, according to a security advisory. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass, as detailed in a report shared with The Hacker News.

- Advertisement -

The affected ranges are versions below 2.31.5 and between 2.32.0 and 2.32.1. n8n rates the issue as High with a CVSS 4.0 score of 8.7, and no CVE had been assigned as of July 27, 2026. Administrators should update rather than rely on n8n’s interim guidance to restrict instance access and workflow editing to fully trusted users.

Exploitation requires a valid account with permission to create or modify workflows and does not require action from another user. A successful exploit executes commands with the privileges of the n8n process, potentially exposing the N8N_ENCRYPTION_KEY and allowing decryption of stored credentials.

Security Joes discovered that in version 2.31.4, the VariablePolyfill.ts handler placed ArrowFunctionExpression in an explicit no-op branch, enabling a concise arrow body such as () => process to resolve to the real Node.js global. Separately, n8n’s property checks inspect static property names in member expressions, but Reflect.get() receives the property as a function argument, allowing recovery of process.getBuiltinModule to load child_process and run a host command.

The fixed rewriter adds a dedicated ArrowFunctionExpression handler that routes a bare identifier in a concise arrow body through the data context. Security Joes’ research team stated: “Neither alone is sufficient. Neither was covered by tests.”

- Advertisement -

Researchers identified the residual escape on July 14 and reported it through n8n’s vulnerability disclosure program on July 15, with fixed releases published on July 22. Defenders should review recently created workflows for unexpected arrow functions and hunt for shells spawned as children of the n8n process, rotating credentials where suspicious activity is found.

The finding extends a series of expression-sandbox escapes n8n has patched since 2025, following CVE-2026-27577, a 9.4-rated escape fixed in February after researchers found the process object slipped through the same identifier-rewriting layer. In affected deployments storing broadly privileged credentials or reaching sensitive internal systems, an attacker with a workflow-edit account can execute commands as the n8n process.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Tesla signs $30B unused credit lines for the AI and robotics

Tesla signed $30 billion in unused senior unsecured bank facilities, including a $20 billion...

New Spectre-v2 CPU Variant ‘BTR’ Hits JIT Engines

Academics disclosed a new Spectre-v2 CPU vulnerability variant, Branch Target Reuse (BTR), affecting JIT...

Cboe, S&P Extend Deal, Eye Tokenized Options

Cboe Global Markets and S&P Dow Jones Indices extended their exclusive licensing agreement through...

OpenAI launches Dots assistant, seeks $30B funding

OpenAI launched "Dots," a persistent virtual assistant operating computers and debugging software autonomously.The company...

Healey jabs Farage with ‘BTC account’ Truss comparison

UK Chancellor John Healey mocked Nigel Farage's fiscal plans by comparing them to a...

Must Read

How Much Money Do You Need To Start In Crypto?

TL;DR -If you are wondering How Much Money Do You Need To Start In Crypto, note that is less than you are probably thinking....
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading