Junglewise Threat Intelligence

n8n expression sandbox escape via arrow functions

Severity: high · CVSS 8.7 · Published 2026-07-22

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool used to connect different software services. A security vulnerability allows an authorized user to bypass safety restrictions by using specially crafted code expressions. This could allow an attacker to execute unauthorized commands directly on the server hosting the n8n application, potentially leading to a full system takeover or data theft.

Technical details

A sandbox escape vulnerability exists in n8n's expression evaluation engine. Authenticated users with workflow creation or modification privileges can bypass the expression sandbox by utilizing crafted JavaScript arrow functions. This bypass allows for arbitrary system command execution (RCE) on the host operating system. The vulnerability is classified as Code Injection (CWE-94) and has been addressed by improving the validation of function bodies within the sandbox. Patches are available in versions 2.31.5 and 2.32.1.

Affected products

  • n8n-io n8n < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: disclosed
  • 2026-07-22: patched
  • 2026-07-22: advisory

References

Related threats