SECURITY·중요도 8·2026. 07. 27.·The Hacker News
n8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n Process
── KO ──────────────────
n8n의 보안 취약점이 수정되어, 인증된 사용자가 OS 명령어를 실행할 수 있는 문제를 해결하였다.
n8n 플랫폼에서 발견된 고위험 보안 취약점이 패치되었다. 이 취약점은 인증된 워크플로 편집자가 n8n 프로세스에서 운영 체제 명령어를 실행할 수 있는 가능성을 열어주었다. 보안 전문가들은 n8n의 이전 취약점 수정 사항을 조사하는 과정에서 이를 발견하였다. 영향을 받은 버전은 2.31.5 미만 및 2.32.0 이상 2.32.1 미만이다.
── EN ──────────────────
n8n patched a security flaw allowing workflow editors to execute OS commands as the n8n process.
A high-severity security vulnerability in n8n has been patched. This flaw allowed authenticated workflow editors to execute operating system commands on the server. Security researchers discovered the issue while investigating a previous fix for another bypass in n8n. Affected versions include versions earlier than 2.31.5 and versions between 2.32.0 and 2.32.1.