Impact
The flaw resides in the Git node, which writes a branch..remote value into the repository configuration without validating it. An authenticated workflow editor can point the node at a repository path accessible to the n8n daemon. The following fetch or pull then resolves the remote from this configuration instead of the supplied parameter, providing the editor with the contents of the local repository. This leads to an unauthorized read of any local repository that the n8n process can access, exposing sensitive data. The weakness is a directory traversal and improper validation issue (CWE-22, CWE-73).
Affected Systems
n8n versions prior to 1.123.76, 2.37.7, and 2.38.2 are affected. The product is the widely used n8n open‑source workflow automation platform.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity. An EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit requires an authenticated workflow editor, so the attack vector is local and relies on legitimate credentials. Once authenticated, an attacker can read any local repository or file that the n8n process can access, which may contain confidential code or data.
OpenCVE Enrichment
Github GHSA