n8n Sandbox Escape Vulnerability Allows OS Command Execution

n8n Sandbox Escape Vulnerability Allows OS Command Execution

First seen 30 Jul 2026, 01:27 UTC Aiweekly.CoAyautomatewww.securityjoes.com 76% similarity 70.5

Article Content

Browse articles
ThreatCluster

On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted JavaScript expressions. The vulnerability arises from a failure in the expression sandbox, enabling access to the Node.js process object. Security Joes discovered the issue while testing a previous fix (CVE-2026-27577) for a similar vulnerability. Successful exploitation could expose sensitive credentials, including the n8n encryption key. The vulnerability affects self-hosted n8n instances, while n8n Cloud users are protected. No CVE has been assigned as of the latest reports. Users are advised to upgrade to versions 2.31.5 or 2.32.1 to mitigate the risk.

Key Points: • n8n patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) on July 22, 2026. • The flaw allows authenticated users to execute OS commands via JavaScript expressions. • Self-hosted n8n instances are vulnerable until upgraded to versions 2.31.5 or 2.32.1.

ThreatCluster AI How this analysis works

Timeline

2025-12-22
Public exploit for CVE-2025-68613 released
A proof-of-concept exploit appeared on GitHub, lowering the barrier for opportunistic attackers.
GitHub
2026-02-04
CVE-2026-25049 published
A destructuring bypass vulnerability in n8n was disclosed, rated CVSS 9.9.
Ayautomate
2026-02-25
CVE-2026-27577 published
Another sandbox escape vulnerability in n8n was published, rated CVSS 9.4.
Ayautomate
2026-07-14
New vulnerability identified
Security Joes discovered a new sandbox escape vulnerability in n8n while testing CVE-2026-27577.
Security Joes
2026-07-22
Patch released for GHSA-gv7g-jm28-cr3m
n8n released a patch for the sandbox escape vulnerability, affecting versions below 2.31.5 and between 2.32.0 and 2.32.1.
Ayautomate
2026-07-27
No CVE assigned yet
As of this date, no CVE has been assigned for the newly discovered vulnerability in n8n.
Aiweekly.Co

Community

Browse all →

Tracked Entities in This Story

N8n