GHSA-rcv6-pvrj-4xcg: n8n: Authenticated code execution in the n8n Git node
Summary
Authenticated users in n8n (a workflow automation platform) with permission to create workflows could run arbitrary code on the server using the Git node (a component that handles Git repository operations). An attacker could exploit this by setting up a malicious Git repository with hooks (scripts that automatically run during Git operations) to execute commands with the privileges of the n8n process.
Solution / Mitigation
The vulnerability has been fixed in n8n versions 1.123.67, 2.31.5, and 2.32.1. Users should upgrade to one of these versions or later. If immediate upgrade is not possible, temporary workarounds include: restricting instance access to trusted users only, disabling the Git node by adding 'n8n-nodes-base.git' to the 'NODES_EXCLUDE' environment variable, or restricting network traffic leaving the n8n instance. The source notes these workarounds 'do not fully remediate the risk and should only be used as short-term mitigation measures.'
Classification
Affected Vendors
Affected Packages
Related Issues
CVE-2026-63086: text-generation-inference through 3.3.7 contains a server-side request forgery (SSRF) vulnerability in the OpenAI-compat
CVE-2026-34371: LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the e
Original source: https://github.com/advisories/GHSA-rcv6-pvrj-4xcg
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 85%