Path Traversal Vulnerability in n8n Git Node Operations
CVE-2026-72770
7.1HIGH
What is CVE-2026-72770?
Versions of n8n prior to 1.123.67 exhibit a path traversal vulnerability within the Git node's operations, including fetch, pull, and push-tags. This flaw allows authenticated users, particularly those with rights to create or execute workflows, to circumvent repository-path containment checks. By exploiting this vulnerability, they can direct allowlisted remote configurations at local paths outside of the designated sandbox environment. This may lead to the exposure and retrieval of arbitrary Git repositories as well as their associated files and history.
Affected Version(s)
n8n 0 < 1.123.67
n8n 0 < 2.32.1
n8n 0 < 2.31.5
