Detects n8n instances where the Merge node's Combine by SQL mode runs AlaSQL in the main Node.js process with a bypassable denylist. An authenticated user can escape the sandbox via JavaScript prototype chain traversal using AlaSQL's arrow operator to execute arbitrary OS commands, read the credential encryption key, and decrypt all stored secrets. Versions <1.123.27, <2.13.3, and 2.14.0 affected.
Is your app exploitable through CVE-2026-33660?
Scan your domain free