arXiv · 2609.33413
Weird Machine Compositors: Exploiting AI Orchestration at the Expression Layer
Abstract
Orchestration platforms secure user-provided expressions through enumerate and block sandboxing: AST rewriting, runtime property blocklists, template sandbox environments. We demonstrate that these sandboxes are weird machines whose instruction set is the underlying language specification, and that the enumerate and block approach is unfixable, following the same trajectory that led to the deprecation of past sandboxing technologies such as Java's SecurityManager and vm2. We validate this claim through three rounds of escalating bypasses against n8n's expression sandbox (three CVEs, two CVSS 9.4, one unauthenticated), and frame these findings within a broader pattern of sandbox failures across the orchestration products category. We identify a trust laundering pattern where orchestration pipelines and applications move attacker controlled input from untrusted to fully credentialed through transformations that strip taint at each level. AI-assisted enumeration accelerates the discovery of these coverage gaps, compressing the timeline between a sandbox's deployment and its compromise. We provide an AST coverage analysis methodology, an accompanying open-source tool, and a defensive playbook that includes policy inversion (allowlist over blocklist) as a structural mitigation.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Eilon Cohen, Ariel Fogel. 2026-09-27. Weird Machine Compositors: Exploiting AI Orchestration at the Expression Layer. https://arxiv.org/abs/2609.33413
Cite the original work for its findings. Save a collection to share your selection of sources.