Hacker News
new
top
best
ask
show
job
Breaking n8n's Expression Sandbox into RCE (CVE-2026-27577) with striga.ai
(
www.striga.ai
)
7 points
by
redfr0g
6 hours ago
2 comments
redfr0g
6 hours ago
How Striga uncovered a critical sandbox escape and unsanitized node name injection in n8n's expression engine, chaining them into full Remote Code Execution.
hackerman70000
5 hours ago
This is why AST-based sandboxing in JavaScript is fundamentally fragile, every new syntax feature is a potential gap