Vulnerability research / published advisory

n8n: a disclosed sandbox escape

The vendor published GHSA-6xcw-7xm6-48c6 on September 2, 2026. The advisory includes the reporter credit.

Outcome and scope

The advisory rates the issue High (CVSS 7.7). It concerns code execution through the legacy expression engine; the vendor identifies the vm engine as unaffected. The advisory is the authority for affected versions and remediation.

My contribution

Discovery, local verification, and reporting to the vendor. This portfolio entry provides the public acknowledgment and bounded outcome. Detailed reproduction material is not included here.

Exploit-detail publication is held until October 2, 2026 under the disclosure terms recorded for this research. Until then, this entry remains a general disclosure record.

Read the vendor advisory / Back to projects