PatchSiren cyber security CVE debrief
CVE-2026-72767 n8n-io CVE debrief
CVE-2026-72767 is a remote code execution vulnerability in n8n's Git node, affecting versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. Authenticated users with workflow creation and execution rights can exploit this by staging a crafted local repository, leading to arbitrary command execution as the n8n process user. Both self-hosted and cloud instances are impacted.
- Vendor
- n8n-io
- Product
- n8n
- CVSS
- HIGH 8.7
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-11
- Original CVE updated
- 2026-09-09
- Advisory published
- 2026-08-11
- Advisory updated
- 2026-09-09
Who should care
Defenders responsible for n8n instances, workflow configurations, and user management should assess exposure and apply mitigations. This includes verifying n8n instance versions and configurations, assessing workflow permissions and Git node usage, and applying patches or mitigations provided by the vendor. Additionally, defenders should monitor for suspicious workflow activity and Git node usage, review compensating controls for exposed systems, and track
Why it matters
CVE-2026-72767 is a high-severity remote code execution vulnerability in n8n's Git node. Authenticated users with workflow creation and execution rights can exploit this vulnerability, impacting both self-hosted and cloud instances. Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.
- Potential for arbitrary command execution as the n8n process user.
- Exposure of self-hosted and cloud instances.
- Need for verification of workflow configurations and user permissions.
- Priority for applying patches or mitigations to prevent exploitation.
Technical summary
The vulnerability exists in the Git node of n8n, allowing authenticated users with workflow creation and execution rights to stage a crafted local repository. This causes git to run hooks under default git security settings, leading to arbitrary command execution as the n8n process user. The affected versions are before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. The vulnerability impacts both self-hosted and cloud instances. Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.
Defensive priority
Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.
Recommended defensive actions
- Verify n8n instance versions and configurations to determine exposure.
- Assess workflow permissions and Git node usage.
- Apply patches or mitigations provided by the vendor.
- Monitor for suspicious workflow activity and Git node usage.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record and NVD entry provide details on the vulnerability, affected versions, and CVSS score. Vendor advisories and additional references are available. The vulnerability exists in n8n versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. Authenticated users with workflow creation and execution rights can exploit this vulnerability. Both self-hosted and cloud instances are impacted. Defenders should verify exposure, assess workflow configurations, and apply vendor patches or mitigations.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72767 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72767
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72767 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72767
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/n8n-io/n8n/security/advisories/GHSA-rcv6-pvrj-4xcg
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/n8n-before-remote-code-execution-via-git-node
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.