Executive brief
A security flaw in the n8n 'computer-use' package fails to restrict shell commands on Linux and Windows systems. While intended to run in a secure 'sandbox,' commands on these operating systems can access the entire host file system and network. This could allow an authorized user to view sensitive files or interfere with the server's internal network.
Technical details
The @n8n/computer-use package in n8n fails to implement sandboxing for its shell tool on Linux and Windows platforms, as enforcement was only active on macOS. This results in an OS Command Injection-like scenario where commands executed by the agent run with the full privileges of the n8n process. An attacker with high privileges (sufficient to trigger the computer-use agent) can achieve unrestricted read/write access to the host filesystem and reach internal network resources. The vulnerability is remediated in versions 2.29.8 and 2.30.1 by integrating 'bubblewrap' for Linux sandboxing and disabling the tool if a secure environment cannot be established.
Affected products
- n8n-io n8n < 2.29.8, >= 2.30.0 < 2.30.1
Timeline
- 2026-07-08: disclosed: Initial disclosure by vendor
- 2026-07-22: advisory: GitHub Advisory published
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-fpg6-x68q-5793
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- https://www.vulncheck.com/advisories/n8n-before-shell-sandbox-bypass-on-linux-windows
- https://api.github.com/repos/n8n-io/n8n/security-advisories/GHSA-fpg6-x68q-5793