Executive brief
n8n is a workflow automation platform that allows users to build and execute automated processes. An authenticated user with workflow creation or modification permissions can exploit arrow function expressions to bypass the security sandbox and execute arbitrary system commands on the host server, compromising the entire system.
Technical details
This is a sandbox escape vulnerability in n8n's expression evaluation engine (CWE-94: Code Injection). The root cause is improper validation of arrow function bodies in expressions, allowing an attacker to break out of the intended sandbox context. An authenticated user with workflow creation/modification permissions can craft malicious expressions using arrow functions to gain unauthenticated remote code execution on the underlying host. The attack requires authentication and workflow edit permissions but no user interaction. The vulnerability has been patched in n8n versions 2.31.5 and 2.32.1.
Affected products
- n8n n8n all versions before 2.31.5 and 2.32.1
Timeline
- 2026-07-22: disclosed: Vulnerability disclosed via GitHub Security Advisory GHSA-gv7g-jm28-cr3m
- 2026-07-22: patched: Fixed in n8n 2.31.5 and 2.32.1