Executive brief
n8n is a popular workflow automation tool used to connect different software services. A security flaw in its Git integration allows an authorized user to bypass security restrictions and run malicious code on the server hosting the application. This could lead to a full system takeover, data theft, or disruption of automated business processes.
Technical details
A Time-of-Check Time-of-Use (TOCTOU) race condition exists in the Git node's 'clone' operation. An authenticated attacker can bypass path validation by replacing a legitimate directory with a symbolic link after the path has been verified but before the git clone execution begins. This allows the attacker to write a malicious repository into the community node directory. Upon the next system restart, n8n loads the malicious repository as a custom node, executing arbitrary JavaScript in the context of the server. The vulnerability affects both self-hosted and cloud instances where users have permission to create workflows using the Git node. Patches are available in versions 1.123.64, 2.29.8, and 2.30.1.
Affected products
- n8n-io n8n < 1.123.64, >= 2.0.0-rc.0 < 2.29.8, >= 2.30.0 < 2.30.1
Timeline
- 2026-07-08: disclosed: Initial disclosure by researcher
- 2026-07-22: advisory: GitHub Advisory published
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-g3r5-9h93-4j2c
- https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.64
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.29.8
- https://github.com/n8n-io/n8n/releases/tag/n8n@2.30.1
- https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-git-clone