PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-72767 n8n-io CVE debrief

CVE-2026-72767 is a remote code execution vulnerability in n8n's Git node, affecting versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. Authenticated users with workflow creation and execution rights can exploit this by staging a crafted local repository, leading to arbitrary command execution as the n8n process user. Both self-hosted and cloud instances are impacted.

Vendor
n8n-io
Product
n8n
CVSS
HIGH 8.7
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-11
Original CVE updated
2026-09-09
Advisory published
2026-08-11
Advisory updated
2026-09-09

Who should care

Defenders responsible for n8n instances, workflow configurations, and user management should assess exposure and apply mitigations. This includes verifying n8n instance versions and configurations, assessing workflow permissions and Git node usage, and applying patches or mitigations provided by the vendor. Additionally, defenders should monitor for suspicious workflow activity and Git node usage, review compensating controls for exposed systems, and track

Why it matters

CVE-2026-72767 is a high-severity remote code execution vulnerability in n8n's Git node. Authenticated users with workflow creation and execution rights can exploit this vulnerability, impacting both self-hosted and cloud instances. Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.

  • Potential for arbitrary command execution as the n8n process user.
  • Exposure of self-hosted and cloud instances.
  • Need for verification of workflow configurations and user permissions.
  • Priority for applying patches or mitigations to prevent exploitation.

Technical summary

The vulnerability exists in the Git node of n8n, allowing authenticated users with workflow creation and execution rights to stage a crafted local repository. This causes git to run hooks under default git security settings, leading to arbitrary command execution as the n8n process user. The affected versions are before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. The vulnerability impacts both self-hosted and cloud instances. Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.

Defensive priority

Defenders should prioritize verifying exposure, assessing workflow configurations, and applying vendor patches or mitigations.

Recommended defensive actions

  • Verify n8n instance versions and configurations to determine exposure.
  • Assess workflow permissions and Git node usage.
  • Apply patches or mitigations provided by the vendor.
  • Monitor for suspicious workflow activity and Git node usage.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The CVE record and NVD entry provide details on the vulnerability, affected versions, and CVSS score. Vendor advisories and additional references are available. The vulnerability exists in n8n versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. Authenticated users with workflow creation and execution rights can exploit this vulnerability. Both self-hosted and cloud instances are impacted. Defenders should verify exposure, assess workflow configurations, and apply vendor patches or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-72767 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-72767

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-72767 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72767

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.