Junglewise Threat Intelligence

CVE-2026-65598: n8n TOCTOU race condition in Git node clone operation

CVE-2026-65598 · Severity: high · CVSS 4 · Published 2026-07-22

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a popular workflow automation tool used to connect different software services. A security flaw in its Git integration allows an authorized user to bypass security restrictions and run malicious code on the server hosting the application. This could lead to a full system takeover, data theft, or disruption of automated business processes.

Technical details

A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the Git node's 'clone' operation. An authenticated attacker can bypass path validation by replacing a legitimate directory with a symbolic link after the path has been verified but before the git clone execution begins. This allows the attacker to write a malicious repository into the community node directory. Upon the next system restart, n8n loads the malicious repository as a custom node, executing arbitrary JavaScript in the context of the server. The vulnerability affects both self-hosted and cloud instances where users have permission to create workflows using the Git node. Patches are available in versions 1.123.64, 2.29.8, and 2.30.1.

Affected products

  • n8n-io n8n < 1.123.64, >= 2.0.0-rc.0 < 2.29.8, >= 2.30.0 < 2.30.1

Timeline

  • 2026-07-08: disclosed: Initial disclosure by researcher
  • 2026-07-22: advisory: GitHub Advisory published

References

Related threats