cve.threatint.com
Remote Code Execution Vulnerability in n8n Git Node (CVE-2026-77084)
Ask AI about this cluster
Analyzing cluster data...
Referenced clusters:
Something went wrong. Please try again.
Article Content
A remote code execution vulnerability (CVE-2026-77084) has been identified in n8n versions prior to 1.123.69 and 2.x before 2.33.4/2.34.1. The Git node in these versions executes certain repository-local git configuration values without proper neutralization, allowing an attacker to execute arbitrary code as the n8n process user. Exploitation requires a separate file-write vulnerability to insert malicious configuration values into the repository. Currently, there is no evidence of public proof-of-concept or active exploitation. Users are advised to update to the patched versions and restrict repository write access. The CVSS score for this vulnerability is 4.0, indicating a medium severity level. The vulnerability was published on August 20, 2026.
Key Points: • CVE-2026-77084 affects n8n versions prior to 1.123.69 and 2.x before 2.33.4/2.34.1. • The vulnerability allows remote code execution via unneutralized git configuration values. • Patches are available, and users are urged to update and restrict repository access.