Remote Code Execution Vulnerability in n8n Git Node
CVE-2026-77084

7.7HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
20 August 2026

What is CVE-2026-77084?

n8n is affected by a vulnerability within the Git node, which improperly processes repository-local git configuration values. This flaw allows unauthorized code execution as the n8n process user when interacting with a repository that contains a crafted configuration value. It is crucial to note that this vulnerability requires an additional file-write flaw for exploitation to occur, emphasizing the need for robust security practices to protect repositories.

Affected Version(s)

n8n 0 < 1.123.69

n8n 2.34.0 < 2.34.1

n8n 2.0.0 < 2.33.4

References

CVSS V4

Score:
7.7
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.