Description
n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical URL string pass the file-access check while git resolved it outside the sandbox. A subsequent fetch or pull read a git repository outside N8N_RESTRICT_FILE_ACCESS_TO and merged its objects into the user's own repository, where their contents could be read back. The issue is fixed in n8n 1.123.76, 2.37.7, and 2.38.2, which resolve the remote reference from the directory git actually operates in before applying the sandbox check. As a workaround, the Git node can be disabled by adding n8n-nodes-base.git to NODES_EXCLUDE.
Published: 2026-09-16
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality breach via sandbox escape
Action: Patch
AI Analysis

Impact

n8n is a workflow automation platform that includes a Git node. In component versions before 1.123.76, 2.37.7, and 2.38.2, the node verifies a relative remote URL against a configured repositoryPath but then runs git with that path as its working directory. Git climbs up to the repository root and resolves the same relative URL from that higher level, allowing an authenticated user who places their repository one level below the configured path to craft a URL that passes the access check while actually pointing outside the sandbox. The result is that the user can fetch data from a repository beyond the N8N_RESTRICT_FILE_ACCESS_TO boundary and merge objects into their own repository, exposing confidential content to the member.

Affected Systems

The vulnerability affects the n8n workflow automation platform (n8n-io:n8n). Any installation running a version prior to 1.123.76, 2.37.7, or 2.38.2 is vulnerable because it contains the unpatched Git node.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score of <1% suggests the likelihood of exploitation is low under current conditions. The issue is not listed in the CISA KEV catalog. The attack requires an authenticated member with permission to configure the Git node. By supplying a crafted relative URL, an attacker can cause git to resolve a repository outside the sandbox, enabling read access to files outside the restricted area. No elevated privileges are needed, but the vulnerability allows confidential information leakage to authorized users.

Generated by OpenCVE AI on September 18, 2026 at 05:50 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade n8n to version 1.123.76, 2.37.7, or 2.38.2 or newer to apply the fix that resolves the remote reference before the sandbox check.
  • If an upgrade is not feasible, disable the vulnerable Git node by adding n8n-nodes-base.git to the NODES_EXCLUDE configuration to prevent execution of that functionality.
  • Review and tighten the N8N_RESTRICT_FILE_ACCESS_TO setting and audit repository structures to ensure users cannot place repositories just below the configured path, thereby reducing the attack surface.

Generated by OpenCVE AI on September 18, 2026 at 05:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 21 Sep 2026 22:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 16 Sep 2026 22:00:00 +0000

Type Values Removed Values Added
Description n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git walked up to the enclosing repository's top level and resolved the same relative URL from there. An authenticated user (member) who nested the repository one level below the configured path could therefore make an identical URL string pass the file-access check while git resolved it outside the sandbox. A subsequent fetch or pull read a git repository outside N8N_RESTRICT_FILE_ACCESS_TO and merged its objects into the user's own repository, where their contents could be read back. The issue is fixed in n8n 1.123.76, 2.37.7, and 2.38.2, which resolve the remote reference from the directory git actually operates in before applying the sandbox check. As a workaround, the Git node can be disabled by adding n8n-nodes-base.git to NODES_EXCLUDE.
Title n8n before 1.123.76 Sandbox Escape via Git Relative URL
First Time appeared N8n
N8n n8n
Weaknesses CWE-426
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
Vendors & Products N8n
N8n n8n
References
Metrics cvssV3_1

{'score': 5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:N'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-21T20:52:50.074Z

Reserved: 2026-09-16T13:47:49.170Z

Link: CVE-2026-92587

cve-icon Vulnrichment

Updated: 2026-09-21T16:22:44.790Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-16T22:18:29.293

Modified: 2026-09-22T20:25:55.870

Link: CVE-2026-92587

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-18T08:00:06Z

Weaknesses