N8N · N8N · CVE-2026-85168
**Name of the Vulnerable Software and Affected Versions**
n8n versions prior to 1.123.73
n8n versions prior to 2.35.4
n8n versions prior to 2.36.2
**Description**
A remote code execution issue exists in the Git node. The node fails to reset the `content-filter` and `merge-driver` configuration key families before operations. If a repository contains local configurations setting these keys with a matching attribute pattern, git executes the configured command during Add, Commit, Checkout, or Pull operations. The command is executed with the privileges of the n8n process user.
**Recommendations**
Update to version 1.123.73 or later.
Update to version 2.35.4 or later.
Update to version 2.36.2 or later.