Login
← All news

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

The Hacker News Security

n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n's February fix for CVE-2026-27577 for another bypass. The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5…

Read the full story on The Hacker News https://thehackernews.com/2026/07/n8n-sandbox-escape-lets-workflow.html
Attacks like this land on ordinary sites far more often than on chosen targets. If you would rather your site never became the story, CrockyHost hosting ships with daily backups, automatic updates and a firewall we manage.