Aiweekly.Co
n8n Sandbox Escape Vulnerability Allows OS Command Execution
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Cluster AI
Ask questions about this threat cluster with AI-powered analysis.
Get Researcher $29.99/moArticle Content
On July 22, 2026, n8n released a patch for a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) rated 8.7 on CVSS 4.0. This flaw allows authenticated users to execute operating system commands via crafted JavaScript expressions. The vulnerability arises from a failure in the expression sandbox, enabling access to the Node.js process object. Security Joes discovered the issue while testing a previous fix (CVE-2026-27577) for a similar vulnerability. Successful exploitation could expose sensitive credentials, including the n8n encryption key. The vulnerability affects self-hosted n8n instances, while n8n Cloud users are protected. No CVE has been assigned as of the latest reports. Users are advised to upgrade to versions 2.31.5 or 2.32.1 to mitigate the risk.
Key Points: • n8n patched a high-severity sandbox escape vulnerability (GHSA-gv7g-jm28-cr3m) on July 22, 2026. • The flaw allows authenticated users to execute OS commands via JavaScript expressions. • Self-hosted n8n instances are vulnerable until upgraded to versions 2.31.5 or 2.32.1.