n8n patches sandbox flaw: what matters about OS command execution risk

Colleagues, I’d like to highlight a cybersecurity update: n8n has fixed a high-severity vulnerability in expression-sandbox.
What happened:
- An authenticated editor could bypass the sandbox and execute OS commands on the server with the privileges of the n8n process.
- Affected versions: <2.31.5 and >=2.32.0,<2.32.1.
- Risk: exposure of N8N_ENCRYPTION_KEY, decryption of credentials, and access to internal services.
I would not rely on temporary mitigations alone — the priority is to upgrade as soon as possible and review recently changed workflows for suspicious JavaScript.
Why this matters: flaws in automation platforms can quickly turn into access to sensitive data and infrastructure.
Are you already checking n8n in your environments?
#cybersecurity #n8n #DevSecOps #Vulnerability


Latest comments
No comments yet.