#VU122478 Inclusion of Functionality from Untrusted Control Sphere in n8n - CVE-2025-62726
Published: February 9, 2026
n8n
n8n
Description
The vulnerability allows a remote user to compromise the affected system.
The vulnerability exists in the Git Node component when cloning a remote repository. A remote user can clone a remote repository containing a pre-commit hook and then use the Commit operation in the Git Node to trigger the hook's execution, leading to remote code execution.