PT-2026-70169 · N8N · N8N

·

CVE-2026-72767

·

Published

2026-07-22

·

Updated

2026-08-11

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.67 n8n versions 2.x prior to 2.31.5 n8n versions 2.32.x prior to 2.32.1
Description Authenticated users with permissions to create and execute workflows can achieve remote code execution via the Git node. By staging a crafted local repository, an attacker can trigger git hooks under default security settings to execute arbitrary commands with the privileges of the n8n process user. This issue affects both cloud and self-hosted instances.
Recommendations Update n8n to version 1.123.67 or later. Update n8n 2.x to version 2.31.5 or later. Update n8n 2.32.x to version 2.32.1 or later.

Exploit

Fix

RCE

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72767
GHSA-RCV6-PVRJ-4XCG

Affected Products

N8N