Impact
The vulnerability resides in the Git node of n8n. An authenticated user with rights to create and execute workflows can prepare a carefully constructed local repository that makes Git run its hooks with the default security settings, allowing execution of arbitrary commands as the n8n process user. This gives the attacker the same privileges as the service, enabling full control over the affected instance. The weakness is classified as CWE‑78, an operating system command injection.
Affected Systems
The affected editions are n8n versions 1.x prior to 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. Both self‑hosted and cloud deployments of these versions run on Node.js and are vulnerable.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, but the vulnerability has not yet been recorded in the CISA KEV catalog, suggesting that widespread exploitation has not been observed. The attack path requires a user who can author workflows, so it is not a zero‑day bug that anyone can exploit without access. Nevertheless, from the available data the risk remains high for any environment where such users exist.
OpenCVE Enrichment