On 22 July 2026, n8n disclosed and patched GHSA-gv7g-jm28-cr3m, a CVSS 8.7 sandbox-escape in the JavaScript Code node. In a mid-market estate, workflow automation platforms (n8n, Zapier, Make, Workato, Tray.io) are the most credential-dense systems on the network. A six-point managed cybersecurity playbook: inventory, fast-patch SLA, assume-breach hunt, least-privilege, audit export, credential rotation.
GHSA-gv7g-jm28-cr3m is a CVSS 8.7 sandbox-escape vulnerability in the JavaScript Code node of n8n, the open-source workflow automation platform. It was disclosed and patched on 22 July 2026, with coverage the same day by GitHub Security Advisories, BleepingComputer and The Hacker News. An authenticated workflow editor with permission to edit a Code node could break out of the VM2 or isolated-vm sandbox that n8n uses to run user-supplied JavaScript, and execute arbitrary code as the n8n runtime process, with the process environment, filesystem and network reachability of the n8n host.
Both self-hosted and n8n Cloud deployments running the vulnerable Code-node runtime prior to the 22 July 2026 fixed releases are affected. Self-hosted deployments need to upgrade to the patched build on the vendor's recommended timeline. n8n Cloud tenants were rolled forward by the vendor and should be verified on the patched build via the vendor's status page or support channel.
Because the patch closes the vulnerable code path but does not remediate persistence an attacker installed before the patch landed. In a workflow automation platform, persistence commonly takes the form of malicious workflow edits with delayed triggers, exfiltrated integration credentials, and lateral movement through the downstream systems the tenant authenticates to. An assume-breach hunt over the exposure window is required, and stored credentials with elevated scope should be rotated on principle rather than on evidence.
Because a modern n8n, Zapier, Make, Workato, Tray.io, Pipedream, Windmill or Retool Workflows tenant typically holds active tokens for the CRM, marketing automation, helpdesk, accounting, payment processor, one or more cloud providers, the code host, the observability stack, at least one LLM provider and a long tail of vertical SaaS. A code-execution vulnerability inside that tenant becomes an atomic compromise of everything the tenant authenticates to. The governance model that applies to a dedicated secrets manager should apply to the workflow platform tenant, with adjustments for the execution surface.
One, maintain a living inventory of every platform, tenant, workflow and stored credential with named business owner and rotation date. Two, contract a fast-patch SLA of 24 hours from vendor advisory to production on any CVSS-8-plus or code-execution advisory. Three, run an assume-breach hunt after any sandbox-class advisory, covering workflow-execution logs, edit history, outbound network telemetry and downstream secrets access logs. Four, apply least-privilege on both the edit surface and the execution surface, with SSO plus MFA and workflow-tenant segregation by blast radius. Five, export workflow edits, credential creations and executions to the central SIEM with retention that matches the estate's incident-response policy. Six, rotate stored credentials on a documented cadence, quarterly for standard scopes, monthly for payment, PII, source code or cloud IAM scopes.
Twenty-four hours from vendor advisory to production deployment on any CVSS-8-plus or code-execution advisory on a workflow automation platform. Seventy-two hours on high-severity advisories, seven days on medium-severity. For self-hosted deployments the buyer owns the patch cycle. For hosted deployments the buyer's job is verification and follow-up on the vendor's status page, plus rotation-on-advisory of stored credentials.
Call IT Dev operates cybersecurity, managed IT and technical support engagements from Morocco with nearshore EU-time-zone coverage, delivery in English, French, Spanish and Arabic, a senior security bench (ISO 27001 lead auditors, CISSP-grade and OSCP-grade engineers), and a regulatory posture aligned with CNDP Law 09-08 and GDPR obligations. The six-point playbook is baked into scope on n8n, Zapier, Make, Workato, Tray.io, Pipedream, Windmill and Retool Workflows tenants: inventory, patch SLA, assume-breach hunting, least-privilege reviews, SIEM export and quarterly credential rotation under a named operational owner.
CALL IT DEV — Software, AI and dedicated tech teams — Casablanca | Madrid | Dubai — contact@callitdev.com — +212-537-373777