Input validation error in n8n - #VU146797

 

Input validation error in n8n - #VU146797

Published: September 2, 2026


Vulnerability identifier: #VU146797
CSH Severity: Low
CVSS v4: 5.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: N/A
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote user to disclose sensitive information from local Git repositories.

The vulnerability exists due to improper input validation in the Git node branch remote configuration handling when processing fetch or pull operations after setUpstream updates repository configuration. A remote user can set a crafted branch.<name>.remote value to point to a local repository and disclose sensitive information from local Git repositories.

Exploitation requires workflow-edit permission and access to the Git node.


Affected software

n8n

Remediation

Install security update from vendor's website.

n8n - addressed in versions 1.123.76, 2.37.7, 2.38.2

External References

Related Security Bulletins