n8n Sandbox Escape Allows OS Command Execution
n8n rewrote workflow expressions through an abstract syntax tree sandbox so an authenticated editor could not reach Node.js internals. Security Joes found two bypasses — a concise arrow function resolving to real globals, and Reflect.get() recovering process.getBuiltinModule — which loaded child_process and ran host commands with the privileges of the n8n process. The sandbox held against the property names it inspected, and not against the ones it was handed.
Severity: Unrated · Category: Tool Misuse
Impact: GHSA-gv7g-jm28-cr3m (CVSS 8.7) · OS command execution, N8N_ENCRYPTION_KEY and stored credentials exposed
Source: The Hacker News · Jul 27 2026 · Original source
How Fencio prevents this
The tools worked exactly as designed. The agent called them with the wrong arguments, at the wrong time, or more often than it should have, and no layer checked whether the call made sense before it ran.
Fencio validates every tool call against expected intent: argument ranges, recipients, amounts, and call frequency. Calls that fall outside expected bounds, repeat without idempotency, or touch identity and money are held for confirmation.