The images in this article were generated with artificial intelligence. How we publish
n8n has released patches for an expression sandbox escape vulnerability that allows an authenticated workflow editor to run operating system commands on the server that houses the automation platform. The failure affects versions prior to 2.31.5 and the series 2.32.0 to 2.32.0 inclusive; the corrections are in 2.31.5 and 2.32.1, and the problem is recorded in GitHub as GHSA-gv7g-jm28-cr3m with a CVSS 4.0 score of 8.7. The supplier published the parcheed launches on July 22 after receiving the investigators' report on July 15; there was no CVE assigned on July 27, 2026.
From a technical point of view, the vector takes advantage of two combined weaknesses in the rewriter of the abstract syntax tree (AST) that n8n uses to move JavaScript identifiers to a platform-controlled context. The first is an omission in the management of ArrowFunctionExpression, which allowed a concise form of a stream function - for example, () = > process - to resolve the identifier against the Node.js runtime instead of the safe context. The second is a property check that only inspected static names in member expressions, avoiding that functions like Reflect.get can receive the property requested as argument and be used to recover integrated modules and run child _ process.

The combination of these two failures allowed researchers to recover process.getBuiltinModule, load child _ process and run commands with the privileges of the n8n process. The operation requires only a valid account with permission to create or modify workflows; it does not depend on the interaction of another user. A successful attack can expose the N8N _ ENCRYPTION _ KEY variable and thus decipher N8n-stored credentials, as well as open roads to databases, internal services and cloud endpoints accessible from the host.
Beyond technique, this incident highlights a recurring lesson for low-code / no-code and automations platforms: those who can edit flows are high-value targets. Allow users with access to workflows to have free entry to embedded scripts or expressions increases the attack surface. Operational security requires combining fast patches with strong access controls and secret and privilege policies.
As immediate measures, the key recommendation is to update to the corrected versions (2.31.5 or 2.32.1) in all the affected instances rather than relying only on the provisional mitigation described in your notice. These mitigations - restricting access to workflow editing to fully trusted users - are useful as a temporary measure, but the seller qualifies them as incomplete and short-term.
After the update it is appropriate to perform a range review: to inspect recently created or modified workflows in search of concise arrow functions or JavaScript osfuscado, to audit host logs for unexpected children processes (bash, sh, PowerShell, curl, wget or other invoked by Node.js / n8n) and to seek decipher activity or access to sensitive resources. If suspicious execution is detected, N8N _ ENCRYPTION _ KEY should be rotated, stored credentials rotated and the accounts and accesses involved audited., since the risk of pivot to internal services or APIs in the cloud is real.
In terms of medium and long-term mitigation, organizations should apply role-based access control and strong authentication (MFA / SSO) to clearly separate workflow builders from accounts that only consume automations. It is also recommended to minimize the privileges that n8n-stored credentials have in connected systems, to use limited or temporary credentials where possible, and to segment the network to reduce the scope of a compromised host.

The incident also highlights the importance of safety tests of components that manipulate code or syntax (parsers, AST rewriters, sandboxes). According to the researchers, neither of the two operating conditions was covered by automated tests, which facilitated regression after a previous arrangement in February (CVE-2026-27577) to close a similar escape. The organizations providing these platforms should improve security tests and code revisions for case limits.
If you use n8n Cloud, check with the manufacturer if your environment has the vulnerable version: the public notice did not specify the status of n8n Cloud. For technical references and details of the notice and follow-up, see the notice entry in GitHub GHSA-gv7g-jm28-cr3m and the official release page where the corrected versions appear N8n relays in GitHub. For journalistic context and third-party reports, you can review coverage and analysis in specialized media such as The Hacker News thehackernews.com.
In short: update without delay, do not rely only on administrative mitigation, audit recent changes in workflows and secrets, and treat workflows editing accounts as critical assets in your security policy. The combination of technical patches, access restrictions and a quick forensic response is the best defense against this type of sandbox escape.
Related
More news on the same subject.

FBI and six countries link Integrity Technology Group to entity post theft in SE Asia
On October 8, the FBI and agencies in six countries issued a joint warning that assigns to a Chinese company, Integrity Technology Group, a sustained series of intrusions whose ...

Campaign with LLM and ARTEX attacks South Korean financial institutions and exfilters data
Security researchers have documented a campaign directed against South Korean financial institutions using language-driven attack tools to automate intrusions and data extractio...

ChainDrop campaign exposes tensorlake in npm; version 0.5.144 withdrawal
A package of npm called tensorlake, an SDK in TypeScript oriented to Tensorlake applications and services, was engaged in a supply chain campaign linked to the attack family kno...

Cyber risk in 2026 moves to workflows and IA, according to Voice of the CISO
The data added by five editions of the Voice of the CISO study - including the most recent findings of 2026 - draw a less intense change than risk location: the threat is moving...

Phishing BitB points to advertising professionals and account managers to steal MFA
Security researchers have described a phishing campaign for advertising professionals and account managers that uses a human-operated platform to mimic ad products linked to IA ...

LibreOffice / OpenOffice Calc allows remote source execution when opening ODB / JDBC leaves
Researchers have shown that a malicious spreadsheet can force LibreOffice and Apache OpenOffice to run code controlled by an attacker at the time the file is opened, without sho...

Denmark confirms unauthorized access to the RCP that affected 8.8 million records
The Danish government confirmed that for about ten days in September there were unauthorized access to the Central Peru Register (CPR) the national population database. Accordin...