CVE-2026-72767: n8n before 1.123.67 Remote Code Execution via Git node
n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72767?
The severity of CVE-2026-72767 is rated at 77, indicating a high risk of exploitation.
How do I fix CVE-2026-72767?
To fix CVE-2026-72767, upgrade n8n to version 1.123.67 or later, or 2.x to version 2.31.5 or later.
Who is affected by CVE-2026-72767?
Authenticated users with the rights to create and execute workflows in n8n before the specified versions are affected by CVE-2026-72767.
What type of vulnerability is CVE-2026-72767?
CVE-2026-72767 is classified as an OS Command Injection vulnerability.
What can attackers do with CVE-2026-72767?
Attackers can exploit CVE-2026-72767 to execute arbitrary code on the server through crafted local Git repositories.