Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull resolved the remote from that configuration instead of the checked parameter. An authenticated workflow editor could therefore point Git at any local repository readable by the n8n process and receive its contents through packages/nodes-base/nodes/Git/GenericFunctions.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local File Read via Git Node Configuration Bypass
Action: Immediate Patch
AI Analysis

Impact

The flaw resides in the Git node, which writes a branch..remote value into the repository configuration without validating it. An authenticated workflow editor can point the node at a repository path accessible to the n8n daemon. The following fetch or pull then resolves the remote from this configuration instead of the supplied parameter, providing the editor with the contents of the local repository. This leads to an unauthorized read of any local repository that the n8n process can access, exposing sensitive data. The weakness is a directory traversal and improper validation issue (CWE-22, CWE-73).

Affected Systems

n8n versions prior to 1.123.76, 2.37.7, and 2.38.2 are affected. The product is the widely used n8n open‑source workflow automation platform.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity. An EPSS score is not available and the vulnerability is not listed in CISA KEV. The exploit requires an authenticated workflow editor, so the attack vector is local and relies on legitimate credentials. Once authenticated, an attacker can read any local repository or file that the n8n process can access, which may contain confidential code or data.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update n8n to version 1.123.76, 2.37.7, or 2.38.2 or later to apply the fixed input validation.
  • If an update is not immediately possible, restrict workflow editor accounts to the minimal permissions required and disallow arbitrary repository paths.
  • Run the n8n process under a least‑privileged user account to limit its ability to read local repositories outside the intended workspace.

Generated by OpenCVE AI on September 9, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-qgpw-8g46-w95v n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
History

Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 4.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N'}


Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull resolved the remote from that configuration instead of the checked parameter. An authenticated workflow editor could therefore point Git at any local repository readable by the n8n process and receive its contents through packages/nodes-base/nodes/Git/GenericFunctions.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
Weaknesses CWE-22
CWE-73
References
Metrics cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:34:48.379Z

Reserved: 2026-09-08T16:44:23.781Z

Link: CVE-2026-86995

cve-icon Vulnrichment

Updated: 2026-09-09T13:34:18.772Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:18.103

Modified: 2026-09-10T20:57:05.830

Link: CVE-2026-86995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-11T13:15:14Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

  • CWE-73

    External Control of File Name or Path