Vulnerabilities
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
From CVE fix to fresh bypass: roughly five months after patching CVE-2026-27577, n8n has closed the same class of expression-sandbox escape again — this time reportedly with no CVE of its own, only a security advisory.