File Access Vulnerability in n8n Workflow Automation Platform
CVE-2026-49465
6MEDIUM
What is CVE-2026-49465?
In n8n Workflow Automation Platform, users with authenticated access to create or modify workflows were able to exploit a flaw in the Git node's operations. By supplying a local filesystem path for both cloning and pushing repositories, these users could bypass n8n's file access restrictions. This flaw allowed unauthorized access to local git repository contents that should have been protected, thus compromising data security. The issue has been rectified in versions 1.123.48, 2.21.8, and 2.22.4.
Affected Version(s)
n8n < 1.123.48 < 1.123.48
n8n >= 2.0.0-rc.0, < 2.21.8 < 2.0.0-rc.0, 2.21.8
n8n >= 2.22.0, < 2.22.4 < 2.22.0, 2.22.4
