7 pointsby redfr0g6 hours ago2 comments
  • redfr0g6 hours ago
    How Striga uncovered a critical sandbox escape and unsanitized node name injection in n8n's expression engine, chaining them into full Remote Code Execution.
  • hackerman700005 hours ago
    This is why AST-based sandboxing in JavaScript is fundamentally fragile, every new syntax feature is a potential gap