CVE-2025-62726

8.8

n8n-io · n8n

A remote code execution vulnerability exists in the n8n Git Node component, where cloning a malicious repository allows arbitrary code execution via triggered pre-commit hooks.

Executive summary

A critical remote code execution vulnerability in n8n allows authenticated attackers to execute arbitrary code by manipulating Git repository pre-commit hooks.

Vulnerability

This is a remote code execution flaw (CWE-829) located in the Git Node component. An attacker with low privileges can trigger the execution of arbitrary code within the n8n environment by forcing the platform to commit from a malicious repository containing a pre-commit hook.

Business impact

The ability to execute arbitrary code within the n8n automation platform presents a severe risk to organizational security. Successful exploitation could lead to full system compromise, unauthorized access to sensitive workflows, and the exfiltration of credentials stored within connected third-party services. With a CVSS score of 8.8, this vulnerability is classified as High and requires immediate attention to prevent lateral movement and data theft.

Remediation

Immediate Action: Update n8n instances to version 1.113.0 or later immediately to incorporate the necessary security fixes in the Git Node component.

Proactive Monitoring: Review n8n server logs for unusual Git operations, unexpected process spawns originating from the n8n service account, or unauthorized repository connections.

Compensating Controls: Restrict n8n Git access to known, trusted repositories and implement network egress filtering to prevent the platform from reaching unauthorized external Git servers.

Exploitation status

Public Exploit Available: Yes, multiple public proofs-of-concept exist on GitHub.

Analyst recommendation

Given the potential for full system compromise and the presence of public proof-of-concept code, this vulnerability poses a significant risk to your environment. Administrators should prioritize the update to version 1.113.0 across all self-hosted and cloud-managed n8n instances. Failure to patch may allow attackers to gain persistent access to your automation workflows and integrated credentials.

More n8n-io CVEs

Sources