Symlink Vulnerability in n8n Workflow Automation Platform
CVE-2026-71539

8.9HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-71539?

The n8n workflow automation platform has a vulnerability that allows authenticated users to exploit the Git node clone operation. Before versions 1.123.64, 2.29.8, and 2.30.1, an attacker could manipulate a validated directory by swapping it with a symlink. This would enable the placement of a manipulated repository in the community node directory, leading to the execution of arbitrary code in the server as a custom JavaScript node upon restart. Users are advised to upgrade to the fixed versions to mitigate this security risk.

Affected Version(s)

n8n < 1.123.64 < 1.123.64

n8n >= 2.0.0-rc.0, < 2.29.8 < 2.0.0-rc.0, 2.29.8

n8n >= 2.30.0, < 2.30.1 < 2.30.0, 2.30.1

References

CVSS V4

Score:
8.9
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.