Weird Machine Compositors: Exploiting AI Orchestration at the Expression Layer

📅 2026-09-27
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
This study addresses fundamental security flaws in expression sandboxes within AI orchestration platforms, which are susceptible to bypass and privilege escalation. We demonstrate that such sandboxes inherently function as "weird machines," rendering enumeration-based interception unfixable, and reveal the risks associated with trust-washing patterns and AI-accelerated vulnerability discovery. This work proposes a policy-inversion defense architecture alongside a novel AST coverage analysis methodology. By integrating AST rewriting, runtime property blocking, and template sandboxing, we establish a structured mitigation framework demonstrating the superiority of allowlisting over blocklisting. The research validates three high-severity CVEs in n8n and provides open-source tools and a defense playbook, ultimately uncovering universal principles underlying sandbox failures.
📝 Abstract
Orchestration platforms secure user-provided expressions through enumerate and block sandboxing: AST rewriting, runtime property blocklists, template sandbox environments. We demonstrate that these sandboxes are weird machines whose instruction set is the underlying language specification, and that the enumerate and block approach is unfixable, following the same trajectory that led to the deprecation of past sandboxing technologies such as Java's SecurityManager and vm2. We validate this claim through three rounds of escalating bypasses against n8n's expression sandbox (three CVEs, two CVSS 9.4, one unauthenticated), and frame these findings within a broader pattern of sandbox failures across the orchestration products category. We identify a trust laundering pattern where orchestration pipelines and applications move attacker controlled input from untrusted to fully credentialed through transformations that strip taint at each level. AI-assisted enumeration accelerates the discovery of these coverage gaps, compressing the timeline between a sandbox's deployment and its compromise. We provide an AST coverage analysis methodology, an accompanying open-source tool, and a defensive playbook that includes policy inversion (allowlist over blocklist) as a structural mitigation.
Innovation

Methods, ideas, or system contributions that make the work stand out.

Weird Machine
Trust Laundering
Expression Sandbox Bypass
AST Coverage Analysis
AI-assisted Enumeration
🔎 Similar Papers
No similar papers found.
💼 Related Jobs
No related jobs found.
E
Eilon Cohen
Pillar Security
Ariel Fogel
Ariel Fogel
UW-Madison