File Access Vulnerability in n8n Workflow Automation Platform
CVE-2026-49465

6MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
23 June 2026

What is CVE-2026-49465?

In n8n Workflow Automation Platform, users with authenticated access to create or modify workflows were able to exploit a flaw in the Git node's operations. By supplying a local filesystem path for both cloning and pushing repositories, these users could bypass n8n's file access restrictions. This flaw allowed unauthorized access to local git repository contents that should have been protected, thus compromising data security. The issue has been rectified in versions 1.123.48, 2.21.8, and 2.22.4.

Affected Version(s)

n8n < 1.123.48 < 1.123.48

n8n >= 2.0.0-rc.0, < 2.21.8 < 2.0.0-rc.0, 2.21.8

n8n >= 2.22.0, < 2.22.4 < 2.22.0, 2.22.4

References

CVSS V4

Score:
6
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.