hacker-news · Crawled Jul 27, 2026

n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

1 CVEs
Read original article ↗

AI Summary

n8n has addressed a high-severity sandbox escape vulnerability that allows authenticated workflow editors to execute operating system commands with the privileges of the n8n process. The flaw stems from incomplete sandboxing in expression parsing, where arrow functions and Reflect.get() property checks can be manipulated to access Node.js runtime objects. This could enable attackers to extract encrypted credentials, access internal services, and execute remote code if they have workflow editing permissions. No in-the-wild exploitation has been observed, but organizations are urged to update immediately due to the risk.

AI-extracted · verify before operational use

Extracted Entities 1 found

MITRE ATT&CK TTPs 1 techniques