·Dora Noda·9 min Three JavaScript Quirks, One CVSS 10.0 RCE: What n8n's Sandbox-Escape Chain Means for Every Agent Tool Wired to Your Cluster
Three individually-harmless gaps in n8n's JavaScript sandbox chained into a CVSS 10.0 RCE that reached every stored credential and, on shared instances, the Kubernetes cluster underneath. Here's the exploit chain and what it means for any tool that hands an agent a general-purpose sandbox.
cybersecurity
AI agents
Kubernetes
self-hosting
+1