PT-2026-85000 · N8N · N8N
CVSS v4.0
7.7
High
| Vector | AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
n8n versions prior to 1.123.73
n8n versions prior to 2.35.4
n8n versions prior to 2.36.2
Description
A remote code execution issue exists in the Git node. The node fails to reset the
content-filter and merge-driver configuration key families before operations. If a repository contains local configurations setting these keys with a matching attribute pattern, git executes the configured command during Add, Commit, Checkout, or Pull operations. The command is executed with the privileges of the n8n process user.Recommendations
Update to version 1.123.73 or later.
Update to version 2.35.4 or later.
Update to version 2.36.2 or later.
Exploit
Fix
RCE
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N