Impact
n8n is a workflow automation platform that includes a Git node. In component versions before 1.123.76, 2.37.7, and 2.38.2, the node verifies a relative remote URL against a configured repositoryPath but then runs git with that path as its working directory. Git climbs up to the repository root and resolves the same relative URL from that higher level, allowing an authenticated user who places their repository one level below the configured path to craft a URL that passes the access check while actually pointing outside the sandbox. The result is that the user can fetch data from a repository beyond the N8N_RESTRICT_FILE_ACCESS_TO boundary and merge objects into their own repository, exposing confidential content to the member.
Affected Systems
The vulnerability affects the n8n workflow automation platform (n8n-io:n8n). Any installation running a version prior to 1.123.76, 2.37.7, or 2.38.2 is vulnerable because it contains the unpatched Git node.
Risk and Exploitability
The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of <1% suggests the likelihood of exploitation is low under current conditions. The issue is not listed in the CISA KEV catalog. The attack requires an authenticated member with permission to configure the Git node. By supplying a crafted relative URL, an attacker can cause git to resolve a repository outside the sandbox, enabling read access to files outside the restricted area. No elevated privileges are needed, but the vulnerability allows confidential information leakage to authorized users.
OpenCVE Enrichment