GHSA-gv7g-jm28-cr3m
-
n8n patches sandbox escape that could let workflow editors run server commands
n8n has patched a high-severity sandbox escape in its workflow expression system that could let an authenticated editor run server commands. The flaw affects releases before 2.31.5 and 2.32.1 and needs only a valid workflow-edit account.

