Security researchers disclosed critical remote code execution (RCE) vulnerabilities in popular self-hosted automation/data platforms that rely on sandboxed expression/formula execution. In n8n, JFrog researcher Natan Nehorai reported CVE-2026-1470 (CVSS 9.9), where authenticated users can abuse the platform’s Expression evaluation to escape the sandbox and execute arbitrary code with the privileges of the n8n process, including via a crafted JavaScript payload in an “Edit Fields” block that can reach Node.js capabilities (e.g., invoking child_process). In Grist-Core, Cyera Research Labs detailed CVE-2026-24002 (CVSS 9.1), dubbed Cellbreak, in which a malicious spreadsheet formula can break out of the Pyodide/WASM sandbox and execute OS commands or host-runtime JavaScript, collapsing the intended boundary between untrusted cell logic and host execution.
Mitigations center on upgrading to fixed releases and validating whether affected sandboxing modes are enabled. Grist maintainers said the issue is addressed in Grist 1.7.9 and advised administrators to check the Admin Panel sandboxing setting: instances using gvisor are not affected, while those using pyodide should update. The Grist disclosure also notes the flaw class is similar to prior Pyodide sandbox-escape issues that have impacted other products (including n8n in earlier reporting), reinforcing that blocklist-style sandboxing approaches can be brittle when untrusted code is evaluated in environments with access to host runtime primitives.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A critical n8n vulnerability, CVE-2026-1470, was publicly reported by JFrog Security researcher Natan Nehorai as an authenticated remote code execution flaw in the platform's Expression evaluation system. The report included technical details and a proof-of-concept showing how low-privileged users could escape the sandbox and execute OS commands via Node.js child_process.
Cyera Research Labs publicly disclosed CVE-2026-24002, codenamed 'Cellbreak,' and credited researcher Vladimir Tokarev with its discovery. The disclosure described how a blocklist-based Pyodide sandbox in Grist-Core could be bypassed to achieve host command execution and host-runtime JavaScript execution, and advised mitigations such as using gVisor and avoiding unsafe Deno bypass settings.
Grist released version 1.7.9 to fix CVE-2026-24002, a critical Pyodide sandbox escape in Python formula execution that could lead to remote code execution, filesystem access, and secret exposure. The issue affected the self-hosted open-source Grist-Core product, with exposure depending in part on sandbox configuration.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.