CVE-2026-85168 HIGH

CVE-2026-85168: n8n before 1.123.73 Remote Code Execution via Git Node

Vendor N8N-Io
Product n8n
Weakness CWE-78
Published September 3, 2026
Last update September 4, 2026

CVSS base score

7.7/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together with a matching attribute pattern causes git to execute the configured command during an ordinary Add, Commit, Checkout, or Pull operation. The command runs as the n8n process user.

Key dates

02Disclosure timeline

September 3, 2026 CVE published
September 4, 2026 Record updated

Related vulnerabilities

04Related CVE