Remote Code Execution Vulnerability in n8n Git Node (CVE-2026-77084)

Remote Code Execution Vulnerability in n8n Git Node (CVE-2026-77084)

First seen 20 Aug 2026, 19:58 UTC Feedlycve.threatint.comnvd.nist.govvulnerability.circl.ludb.gcve.eu 88% similarity 57.1

Article Content

Browse articles
ThreatCluster

A remote code execution vulnerability (CVE-2026-77084) has been identified in n8n versions prior to 1.123.69 and 2.x before 2.33.4/2.34.1. The Git node in these versions executes certain repository-local git configuration values without proper neutralization, allowing an attacker to execute arbitrary code as the n8n process user. Exploitation requires a separate file-write vulnerability to insert malicious configuration values into the repository. Currently, there is no evidence of public proof-of-concept or active exploitation. Users are advised to update to the patched versions and restrict repository write access. The CVSS score for this vulnerability is 4.0, indicating a medium severity level. The vulnerability was published on August 20, 2026.

Key Points: • CVE-2026-77084 affects n8n versions prior to 1.123.69 and 2.x before 2.33.4/2.34.1. • The vulnerability allows remote code execution via unneutralized git configuration values. • Patches are available, and users are urged to update and restrict repository access.

ThreatCluster AI How this analysis works

Timeline

2026-08-20
CVE-2026-77084 published
The vulnerability in n8n was disclosed, affecting versions before 1.123.69 and 2.x before 2.33.4/2.34.1.
cve.threatint.com
2026-08-20
Patch released for n8n
Patches were made available for n8n versions 1.123.69, 2.33.4, and 2.34.1 to address the vulnerability.
Feedly
2026-08-20
NVD includes CVE-2026-77084
The National Vulnerability Database published details on CVE-2026-77084, confirming its existence and impact.
nvd.nist.gov

Community

Browse all →

Tracked Entities in This Story