n8n before 1.123.69 (and 2.x before 2.33.4 / 2.34.1) contains a code execution vulnerability in the Git node. The Git node executed certain repository-local git configuration values without neutralizing them, so any subsequent Git node operation against a repository containing a malicious value would execute it as the n8n process user. This is not reachable through the Git node's own configuration controls and requires a separate file-write vulnerability elsewhere to plant the malicious value.
Attack Parameters
Impact Assessment
CVSS Vector v4.0
Weakness Type (CWE)
Vulnerable Products 6
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
|
— |
1.123.69
|
|
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
|
— |
2.34.1
|
|
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:*:*:*
|
— |
2.33.4
|
|
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
|
— |
1.123.69
|
|
N8n N8n
cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
|
2.0.0
|
2.33.4
|
|
N8n N8n
cpe:2.3:a:n8n:n8n:2.34.0:*:*:*:*:node.js:*:*
|
— | — |