Close Menu
    What's Hot

    El-Sayed comes under fire for 'ogre on a pike' leaked comment

    Nvidia Forms Alliance to Back Open-Source A.I. Amid Debate Over Safety

    Hungarian GP: Martin Brundle on ‘relentless’ Lando Norris, Oscar Piastri-Carlos Sainz incident and Malaysia return to F1 calendar | F1 News

    Facebook X (Twitter) Instagram
    Trending
    • El-Sayed comes under fire for 'ogre on a pike' leaked comment
    • Nvidia Forms Alliance to Back Open-Source A.I. Amid Debate Over Safety
    • Hungarian GP: Martin Brundle on ‘relentless’ Lando Norris, Oscar Piastri-Carlos Sainz incident and Malaysia return to F1 calendar | F1 News
    • Iran war update: Mediators are reporting progress in diplomatic efforts in the Middle East
    • Opinion | The Kabbalah Teaching That Changed How I See A.I.
    • The Fight for International Justice Continues
    • Ukrainian Attacks in Crimea Deprive Towns of Power and Water
    • Wellness Influencers Are Pushing ‘Natural’ and Unproven Alternatives to Adderall
    interluknewsinterluknews
    • Home
    • Business
      • Corporate News
      • Industry Insights
      • Startups & Entrepreneurship
      • Technology & Innovation
    • Economy
      • Economic Policy
      • Financial Analysis
      • Inflation & Interest Rates
      • Trade & Markets
    • Global
      • Conflicts & Security
      • Diplomacy
      • Global Trends
      • International Affairs
    • Lifestyle
      • Fashion
      • Food & Dining
      • Personal Development
      • Travel
    • Opinion
      • Columns
      • Editorials
      • Expert Opinions
      • Reader Voices
    • More
      • Politics
        • Elections
        • Government & Policy
        • International Relations
        • Political Analysis
      • Sports
        • Cricket
        • Football / Soccer
        • International Sports
        • Local Sports
      • Technology
        • Artificial Intelligence
        • Cybersecurity
        • Gadgets & Reviews
        • Tech News
      • South Africa News
    Facebook X (Twitter) Instagram
    interluknewsinterluknews
    Cybersecurity

    n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

    adminBy adminJuly 27, 2026No Comments4 Mins Read
    Share Facebook Twitter Pinterest Copy Link Telegram LinkedIn Tumblr Email
    n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Swati KhandelwalJul 27, 2026Vulnerability / Enterprise Security

    n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process

    n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass.

    The affected ranges are and >=2.32.0,. n8n fixed the flaw in versions 2.31.5 and 2.32.1. It tracks the issue as GHSA-gv7g-jm28-cr3m, rates it High with a CVSS 4.0 score of 8.7, and no CVE had been assigned as of July 27, 2026.

    Administrators should update rather than rely on n8n’s interim guidance to restrict instance access and workflow editing to fully trusted users. The advisory describes those controls as incomplete, short-term mitigations. It lists no patched 1.x release and does not say whether n8n Cloud was affected.

    Exploitation requires a valid account with permission to create or modify workflows. It does not require action from another user. A successful exploit executes commands with the privileges of the n8n process.

    Cybersecurity

    Security Joes, in a report shared with The Hacker News, said that access could expose N8N_ENCRYPTION_KEY and allow decryption of credentials stored in n8n. It could also open paths to connected databases, internal services, and cloud endpoints. The firm had not observed exploitation in the wild when its report was prepared. The public advisory does not say whether the flaw was exploited before the fix.

    n8n workflow builders use expressions such as ={{ $json.email }}. An abstract syntax tree rewriter redirects free JavaScript identifiers in those expressions to n8n’s controlled data context rather than the Node.js runtime. In version 2.31.4, VariablePolyfill.ts placed ArrowFunctionExpression in an explicit no-op branch. A concise arrow body such as () => process could therefore resolve process to the real Node.js global instead of the sandboxed value.

    The second blind spot, Security Joes said, was in n8n’s property checks, which inspect static property names in member expressions. Reflect.get() receives the requested property as a function argument. The researchers used that distinction to recover process.getBuiltinModule, load child_process, and run a command on the host.

    They tested the proof-of-concept against n8n 2.30.4 through both the released workflow package and a local n8n instance.

    A comparison of the public 2.31.4 and 2.31.5 source files confirms the arrow-function gap. It does not independently confirm the complete Reflect.get() exploit chain described in Security Joes’ report. The fixed rewriter adds a dedicated ArrowFunctionExpression handler that routes a bare identifier in a concise arrow body through the data context.

    “Neither alone is sufficient. Neither was covered by tests,” Security Joes’ research team said of the two conditions its exploit relied on. Security Joes initially estimated the flaw would land near the 9.4 Critical rating of CVE-2026-27577; the vendor’s published 8.7 is the current score.

    Cybersecurity

    Researchers identified the residual escape on July 14 and reported it through n8n’s vulnerability disclosure program on July 15. n8n published the fixed releases on July 22. Defenders should review recently created or modified workflows for unexpected arrow functions or obfuscated JavaScript. They should also hunt for shells, PowerShell, curl, or wget spawned as children of the n8n or Node.js process. Credentials should be rotated where suspicious workflow execution or host command activity is found.

    The finding extends a series of expression-sandbox escapes n8n has patched since 2025. It follows CVE-2026-27577, a 9.4-rated escape fixed in February after researchers found the process object slipped through the same identifier-rewriting layer untransformed.

    In affected deployments where n8n stores broadly privileged credentials or can reach sensitive internal systems, an attacker who compromises a workflow-edit account can use the flaw to execute commands as the n8n process and reach services accessible from the n8n host.

    Commands editors escape Lets n8n process run sandbox workflow
    Follow on Google News Follow on Flipboard
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
    Previous ArticleA Guide to Iran’s Strategic Islands
    Next Article Central Garden & Pet Company (CENT) M&A Call Transcript
    admin
    • Website

    Related Posts

    Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

    July 27, 2026

    TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

    July 27, 2026

    Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

    July 25, 2026
    Leave A Reply Cancel Reply

    Demo
    Latest Posts

    El-Sayed comes under fire for 'ogre on a pike' leaked comment

    Nvidia Forms Alliance to Back Open-Source A.I. Amid Debate Over Safety

    Hungarian GP: Martin Brundle on ‘relentless’ Lando Norris, Oscar Piastri-Carlos Sainz incident and Malaysia return to F1 calendar | F1 News

    Iran war update: Mediators are reporting progress in diplomatic efforts in the Middle East

    Latest Posts

    Subscribe to News

    Get the latest sports news from NewsSite about world, sports and politics.

    Advertisement
    Demo

    We are a digital news platform delivering timely, accurate, and insightful coverage of politics, global affairs, business, economy, sports, and more. Our mission is to keep readers informed with reliable news, clear analysis, and stories that truly matter.
    We're social. Connect with us:

    Facebook X (Twitter) Instagram Pinterest YouTube

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    Type above and press Enter to search. Press Esc to cancel.

    Powered by
    ...
    ►
    Necessary cookies enable essential site features like secure log-ins and consent preference adjustments. They do not store personal data.
    None
    ►
    Functional cookies support features like content sharing on social media, collecting feedback, and enabling third-party tools.
    None
    ►
    Analytical cookies track visitor interactions, providing insights on metrics like visitor count, bounce rate, and traffic sources.
    None
    ►
    Advertisement cookies deliver personalized ads based on your previous visits and analyze the effectiveness of ad campaigns.
    None
    ►
    Unclassified cookies are cookies that we are in the process of classifying, together with the providers of individual cookies.
    None
    Powered by