Input validation error in n8n - #VU146797
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to disclose sensitive information from local Git repositories.
The vulnerability exists due to improper input validation in the Git node branch remote configuration handling when processing fetch or pull operations after setUpstream updates repository configuration. A remote user can set a crafted branch.<name>.remote value to point to a local repository and disclose sensitive information from local Git repositories.
Exploitation requires workflow-edit permission and access to the Git node.