CVE-2026-72770: n8n before 1.123.67 Path Traversal via Git Node Operations
n8n versions before 1.123.67 contain a path traversal vulnerability in the Git node's fetch, pull, and push-tags operations that allows authenticated users to bypass repository-path containment checks. Attackers with workflow create/execute rights can point allowlisted remote configurations at local paths outside the sandbox to pull arbitrary git repositories and read their files and history.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
n8nto a version that resolves this vulnerability.Fixed in 1.123.67
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72770?
CVE-2026-72770 has a risk score of 51, indicating a moderate severity level.
How do I fix CVE-2026-72770?
To fix CVE-2026-72770, upgrade to n8n version 1.123.67 or later.
What systems are affected by CVE-2026-72770?
CVE-2026-72770 affects n8n versions prior to 1.123.67.
What type of vulnerability is CVE-2026-72770?
CVE-2026-72770 is a path traversal vulnerability in the Git node operations.
Who can exploit CVE-2026-72770?
Authenticated users with workflow create or execute rights can exploit CVE-2026-72770.