Executive brief
n8n is a workflow automation platform that allows users to configure source control integration via SSH. The platform disables SSH host key verification in its SSH configuration, allowing an attacker positioned on the network between n8n and the Git server to intercept the connection, present a fake host key, and inject malicious code into workflows or steal repository data. This vulnerability only affects instances that have explicitly enabled the Source Control feature with SSH configuration.
Technical details
This vulnerability stems from improper SSH configuration in n8n's Source Control feature, which disables SSH host key verification (StrictHostKeyChecking=no) when performing git operations. The attack vector is network-based and requires the attacker to be positioned between the n8n instance and the remote Git server; no authentication or special privileges are needed. An attacker can exploit this to perform a man-in-the-middle attack, presenting a fraudulent SSH host key to redirect git operations to a malicious server, potentially injecting malicious workflows, exfiltrating repository data, or compromising workflow integrity. The vulnerability affects all n8n versions prior to 2.5.0, where the issue has been fixed. Affected instances must have the Source Control feature explicitly enabled and configured to use SSH (a non-default configuration).
Affected products
- n8n n8n before 2.5.0
Timeline
- 2026-03-25: disclosed
- 2026-03-25: patched: Fixed in version 2.5.0