Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected. | |
| Title | n8n before 1.123.67 Remote Code Execution via Git node | |
| First Time appeared |
N8n
N8n n8n |
|
| Weaknesses | CWE-78 | |
| CPEs | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* | |
| Vendors & Products |
N8n
N8n n8n |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-11T15:00:41.363Z
Reserved: 2026-08-10T15:06:16.417Z
Link: CVE-2026-72767
Updated: 2026-08-11T15:00:38.016Z
Status : Received
Published: 2026-08-11T13:19:06.940
Modified: 2026-08-11T16:17:36.737
Link: CVE-2026-72767
No data.
OpenCVE Enrichment
No data.