Impact
n8n versions earlier than 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in the expression engine. The flaw is a CWE-94 (Code Injection) weakness that allows an authenticated user who can create or modify workflows to craft arrow‑function expressions that bypass the expression sandbox and trigger arbitrary system command execution on the host running n8n. This gives the attacker full control over the underlying operating system, effectively compromising confidentiality, integrity, and availability of the system.
Affected Systems
The vulnerable product is n8n from n8n‑io. Versions prior to 2.31.5 and before 2.32.1 are affected. The fix is included in both 2.31.5 and 2.32.1 releases.
Risk and Exploitability
The CVSS score of 8.7 reflects a high severity RCE risk. The EPSS score is not available, indicating insufficient public data on exploitation likelihood, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated attacker with workflow‑creation or modification permissions; thus internal use of n8n or compromised credentials can be used to trigger the exploit. Addressing the issue by upgrading or restricting permissions is essential to mitigate this high‑risk vulnerability.
OpenCVE Enrichment