Patch released n8n rce web-app
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
CVE Tools coverage
n8n has addressed a high-severity sandbox escape vulnerability that could allow authenticated users to execute arbitrary OS commands on the server hosting the automation platform. The flaw, tracked as GHSA-gv7g-jm28-cr3m, affects versions less than 2.31.5 and between 2.32.0 and 2.32.1. Security Joes discovered the issue while testing for potential bypasses of an earlier fix for CVE-2026-27577. The vulnerability allows attackers with workflow editing permissions to run commands under the privileges of the n8n process. Administrators are advised to upgrade to either version 2.31.5 or 2.32.1 immediately.