AE-K9VYGJHV
Computer-use agent's shell tool runs unsandboxed on Linux and Windows because sandbox restrictions were applied only on macOS
SECURITY FAILUREseverity: HIGHcause: VERIFIEDoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
The shell tool in n8n's @n8n/computer-use package applied its sandbox restrictions only on macOS. On Linux and Windows, commands executed by the tool ran without filesystem or network restrictions, giving the computer-use agent process unrestricted host access.
- Framework / agent
- n8n (@n8n/computer-use) · computer-use agent with shell tool
- Remediation attempts
- APPLIED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY n8n: computer-use Shell Sandbox Not Enforced on Linux and Windows — https://github.com/n8n-io/n8n, retrieved 2026-09-29
Symptoms
- Shell commands executed by the computer-use agent on Linux and Windows run without filesystem or network restrictions
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-K9VYGJHV. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.