Improper access control in n8n - #VU139107
Published: July 22, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper access control in the Git node when executing workflows that stage a crafted local repository under the default git security settings. A remote user can create and execute a workflow using the Git node to execute arbitrary code.
Exploitation causes git to run hooks as the n8n process user.