Description
n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Thu, 20 Aug 2026 12:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | n8n before 1.123.69 Remote Code Execution via Git node | n8n before 1.123.69 Remote Code Execution via Git Node Configuration Values |
| References |
Thu, 20 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value. | |
| Title | n8n before 1.123.69 Remote Code Execution via Git node | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-20T11:37:18.086Z
Reserved: 2026-08-20T10:55:09.093Z
Link: CVE-2026-77084
No data.
Status : Received
Published: 2026-08-20T12:16:39.970
Modified: 2026-08-20T12:16:39.970
Link: CVE-2026-77084
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-78
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')