Remote Code Execution Vulnerability in n8n by n8n-io
CVE-2026-85168
7.7HIGH
What is CVE-2026-85168?
The vulnerability present in n8n allows remote code execution through its Git node in specific versions. When certain Git configuration keys are mismanaged, it enables unauthorized command execution during standard Git operations such as Add, Commit, Checkout, or Pull. This occurs if attackers manipulate local configurations to trigger commands that run under the privileges of the n8n process user, thereby posing significant security risks to the application and its data.
Affected Version(s)
n8n 0 < 1.123.73
n8n 0 < 2.36.2
n8n 0 < 2.35.4
