n8n has patched a high-severity expression-sandbox escape that could let an authenticated workflow editor execute operating-system commands on the server running the automation platform. Security Joes found the flaw while probing n8n’s February fix for CVE-2026-27577 for another bypass.
The affected ranges are <2.31.5 and >=2.32.0,<2.32.1. n8n fixed the flaw in versions 2.31.5 and 2.32.1. It tracks the issue as GHSA-gv7g-jm28-cr3m, rates it High with a CVSS 4.0 score of 8.7, and no CVE had been assigned as of July 27, 2026.
Administrators should update rather than rely on n8n’s interim guidance to restrict instance access and workflow editing to fully trusted users. The advisory describes those controls as incomplete, short-term mitigations. It lists no patched 1.x release and does not say whether n8n Cloud was affected.
Exploitation requires a valid account with permission to create or modify workflows. It does not require action from another user. A successful exploit executes commands with the privileges of the n8n process.



Leave a Reply