n8n Patches 8.7-Rated Sandbox Escape Bug Letting Workflow Editors Execute Server Commands
n8n patched a high-severity sandbox escape vulnerability that allowed authenticated admins with workflow-edit permissions to execute operating system commands. Rated 8.7 out of 10, the flaw enabled a crafted expression within a workflow to run code directly as the n8n process.
The vulnerability required no victim interaction to exploit and could expose stored credentials and reachable internal services. The company directed admins to its security channels to apply the update to affected instances.
From the sources (3 posts)
@thehackersnews🛑 A user with n8n workflow-edit rights could turn a crafted expression into OS command execution as the n8n process. This 8.7-rated flaw needs no victim interaction and could expose stored credentials and reachable internal services. Deta
@f1tym1n8n patched a high-severity sandbox escape allowing authenticated users to execute OS commands on the server.
@thecybersechubn8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process