OS Command Injection in n8n - #VU153004
Published: September 30, 2026
Vulnerability details
The vulnerability allows a remote user to execute arbitrary code.
The vulnerability exists due to improper neutralization of repository configuration in the Git node Log operation when executing git commands. A remote user can point the node at a repository whose local configuration they control to execute arbitrary code.
The issue occurs under default settings.