Improper Certificate Validation in n8n - CVE-2026-33724
Published: April 30, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote attacker to disclose sensitive information and modify workflow content.
The vulnerability exists due to improper certificate validation in the SSH command used for git operations when connecting to a remote Git server over SSH for Source Control operations. A remote attacker can present a fraudulent host key in a machine-in-the-middle position to disclose sensitive information and modify workflow content.
Only instances with the Source Control feature explicitly enabled and configured to use SSH are vulnerable.