Improper Certificate Validation in n8n - CVE-2026-33724

 

Improper Certificate Validation in n8n - CVE-2026-33724

Published: April 30, 2026


Vulnerability identifier: #VU128726
CSH Severity: Medium
CVSS v4: 6.3 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-33724
CWE-ID: CWE-295
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to disclose sensitive information and modify workflow content.

The vulnerability exists due to improper certificate validation in the SSH command used for git operations when connecting to a remote Git server over SSH for Source Control operations. A remote attacker can present a fraudulent host key in a machine-in-the-middle position to disclose sensitive information and modify workflow content.

Only instances with the Source Control feature explicitly enabled and configured to use SSH are vulnerable.


Affected software

n8n

How to mitigate CVE-2026-33724

Install security update from vendor's website.

n8n - update to 2.5.0

External References

Related Security Bulletins