n8n vulnerability

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.

Published 11 Aug 2026Updated 18 Sep 20262 sources
CVSS 8.7

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.