GHSA-725q-c4vp-q4cg: Duplicate Advisory: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
highvulnerability
security
Source: GitHub Advisory DatabaseJuly 22, 2026
Summary
n8n (a workflow automation platform) before versions 1.123.64, 2.29.8, and 2.30.1 had a race condition vulnerability (a timing flaw where an attacker can change something between when it's checked and when it's used) in its Git node that let authenticated users execute arbitrary code on the server by swapping a directory for a symlink after validation, allowing them to load malicious custom nodes when n8n restarts.
Solution / Mitigation
Update n8n to version 1.123.64, 2.29.8, or 2.30.1 or later.
Classification
Attack SophisticationModerate
Affected Vendors
Affected Packages
n8n@< 1.123.64
Monthly digest — independent AI security research
Original source: https://github.com/advisories/GHSA-725q-c4vp-q4cg
First tracked: July 22, 2026 at 02:00 PM
Classified by LLM (prompt v3) · confidence: 95%