Impact
n8n versions prior to 1.123.67 allow an authenticated user to perform path traversal through the Git node’s fetch, pull, and push‑tags operations; the software fails to enforce repository‑path containment, enabling the attacker to point authorized Git operations at local file system paths outside the expected sandbox. This flaw permits reading of arbitrary files and the full commit history from those files, representing a significant confidentiality breach without requiring elevated privileges beyond workflow creation or execution rights.
Affected Systems
All deployments of n8n running versions earlier than 1.123.67 are affected. The vulnerability is specific to the n8n‑io:n8n product and does not extend to later releases that incorporate the mitigation.
Risk and Exploitability
The CVSS score of 7.1 highlights a serious risk, but the EPSS metric is not available, so precise likelihood of exploitation is unclear. Because the flaw requires authentication with workflow create/execute rights, a compromised or malicious insider could exploit the vulnerability. The path traversal attack does not depend on network exposure; it can be triggered from within the system once the necessary permissions are present. The vulnerability is not listed in CISA’s KEV catalog, yet the potential for data exfiltration warrants immediate attention.
OpenCVE Enrichment