Intel

AIKIDO-2025-10286

n8n-nodes-base is vulnerable to Sandbox Bypass

Sandbox Bypass Pre-CVE
Found by Aikido Intel before public disclosure or CVE publication.

15

Low Risk

This Affects:

jsn8n-nodes-base
1.1.0 - 1.91.0
Fixed in 1.91.1

TL;DR

Affected versions of this package are vulnerable to sandbox escape in the Pyodide module due to improper argument parsing handling. This could allow the bypass of sandbox restrictions and execute arbitrary code. An attacker could exploit this by crafting malicious inputs that escape sanitization, potentially gaining access to system-level operations or sensitive data.

Who does this affect?

You are affected if you are using a version that falls within the vulnerable range.

Background info

n8n-nodes-base is vulnerable to Sandbox Bypass in versions 1.1.0 - 1.91.0.

How to fix this

Upgrade the n8n-nodes-base library to the patch version.