n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Thu, 20 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | n8n before 1.123.69 Remote Code Execution via Git node | n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values |
| References |
Thu, 20 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value. | |
| Title | n8n before 1.123.69 Remote Code Execution via Git node | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T11:37:18.086Z
Reserved: 2026-08-20T10:55:09.093Z
Link: CVE-2026-77084
No data.
Status : Received
Published: 2026-08-20T12:16:39.970
Modified: 2026-08-20T12:16:39.970
Link: CVE-2026-77084
No data.
OpenCVE Enrichment
Updated: 2026-08-20T22:30:05Z
Weaknesses