Path Traversal Vulnerability in n8n Git Node Operations
CVE-2026-72770

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72770?

Versions of n8n prior to 1.123.67 exhibit a path traversal vulnerability within the Git node's operations, including fetch, pull, and push-tags. This flaw allows authenticated users, particularly those with rights to create or execute workflows, to circumvent repository-path containment checks. By exploiting this vulnerability, they can direct allowlisted remote configurations at local paths outside of the designated sandbox environment. This may lead to the exposure and retrieval of arbitrary Git repositories as well as their associated files and history.

Affected Version(s)

n8n 0 < 1.123.67

n8n 0 < 2.32.1

n8n 0 < 2.31.5

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.