Aiweekly.Co n8n Sandbox Escape Vulnerability Allows OS Command Execution
Article Content
- •n8n patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) on July 22, 2026.
- •The flaw allows authenticated users to execute OS commands via JavaScript expressions.
- •Self-hosted n8n instances are vulnerable until upgraded to versions 2.31.5 or 2.32.1.
On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted JavaScript expressions. The vulnerability arises from a failure in the expression sandbox, enabling access to the Node.js process object. Security Joes discovered the issue while testing a previous fix (CVE-2026-27577) for a similar vulnerability. Successful exploitation could expose sensitive credentials, including the n8n encryption key. The vulnerability affects self-hosted n8n instances, while n8n Cloud users are protected. No CVE has been assigned as of the latest reports. Users are advised to upgrade to versions 2.31.5 or 2.32.1 to mitigate the risk.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (3)
Following this threat?
Track CVE-2025-68613 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Continue Reading
Critical RCE Vulnerability in n8n Disclosed (CVE-2025-68613) CVE-2025-68613 is a critical remote code execution (RCE) vulnerability found in n8n, an open-source workflow automation platform. This flaw allows authenticated users to execute arbitrary code on the server, risking full system compromise. The CVSS score for this vulnerability is 9.9 to 10.0, indicating its severity.…
Critical Zero-Day Vulnerability in Cisco Secure Email Gateway Exploited On September 14, 2026, Cisco disclosed a critical SQL injection vulnerability (CVE-2026-76461) in its Secure Email Gateway, allowing unauthenticated remote attackers to execute arbitrary commands with root privileges. This vulnerability arises from insufficient validation in the email parsing logic. Cisco confirmed…