July 28, 2026
- n8n patched a high-severity expression-sandbox escape (affecting <2.31.5 and 2.32.0–2.32.1) that let an authenticated workflow editor run OS commands as the n8n process; Security Joes found it while probing the February fix for CVE-2026-27577 (The Hacker News). · Vulnerabilities & Exploits