The record
Written from the 1 report below. Nothing here is unsourced.
- n8n has patched a high-severity sandbox escape vulnerability that could let authenticated users with workflow-editing permission run operating-system commands on the server hosting the automation platform.
- Security Joes found the flaw while testing n8n's February fix for an earlier similar bug, and n8n released fixed versions 2.31.5 and 2.32.1 on July 22, rating the issue High with a CVSS 4.0 score of 8.7.
- The company says exploitation requires a valid workflow-editing account, and Security Joes had not seen exploitation in the wild when its report was prepared, though such access could expose stored credentials and connected internal systems.
- Administrators are advised to update promptly, review recent workflows for suspicious code, and rotate credentials if there are signs of misuse, as n8n's interim access restrictions are described as incomplete mitigations.
What to watch next
- Whether a CVE identifier is assigned and whether n8n clarifies if n8n Cloud was affected
- Any reports of exploitation in the wild or additional affected 1.x releases
- Further sandbox escapes in n8n's expression-rewriting layer, given the series of similar bugs since 2025
Coverage1
1 report
English national1
All filed from India
Named India · n8n · Security Joes
The 1 report is listed beside the record.
Ask this story
Answers cite the reports above, or say they can't.
