CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 3247

As cited

Copy frozen at (site build).

vulnerabilities

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n patched a high-severity sandbox escape vulnerability that allowed authenticated workflow editors to execute arbitrary operating system commands on the server. Security Joes discovered the flaw while investigating a prior bypass in n8n's February fix for CVE-2026-27577. The vulnerability affects versions below 2.31.5 and 2.32.0 through 2.32.0, with fixes released in versions 2.31.5 and 2.32.1.

Why it matters: Organizations running n8n are exposed to command execution attacks by any user with workflow editor permissions; immediate patching to 2.31.5 or 2.32.1+ is required to prevent unauthorized server compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

n8n patched a high-severity sandbox escape vulnerability that allowed authenticated workflow editors to execute arbitrary operating system commands on the server. Security Joes discovered the flaw while investigating a prior bypass in n8n's February fix for CVE-2026-27577. The vulnerability affects versions below 2.31.5 and 2.32.0 through 2.32.0, with fixes released in versions 2.31.5 and 2.32.1.

Why it matters: Organizations running n8n are exposed to command execution attacks by any user with workflow editor permissions; immediate patching to 2.31.5 or 2.32.1+ is required to prevent unauthorized server compromise.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary