PT-2026-70169 · N8N · N8N
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.67
n8n versions 2.x prior to 2.31.5
n8n versions 2.32.x prior to 2.32.1
Description
Authenticated users with permissions to create and execute workflows can achieve remote code execution via the Git node. By staging a crafted local repository, an attacker can trigger git hooks under default security settings to execute arbitrary commands with the privileges of the n8n process user. This issue affects both cloud and self-hosted instances.
Recommendations
Update n8n to version 1.123.67 or later.
Update n8n 2.x to version 2.31.5 or later.
Update n8n 2.32.x to version 2.32.1 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N