SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-85168

HIGH · CVSS 8.8 EPSS 0.37% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-03 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

Versions of n8n prior to 1.123.73, 2.35.4, and 2.36.2 are vulnerable to remote code execution through the Git node, which improperly handles specific configuration keys. This flaw allows an attacker to execute arbitrary commands during standard Git operations, potentially compromising the n8n process user. Organizations using affected n8n versions should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-85168
Severity
HIGH
CVSS
8.8
EPSS
0.37%

Original NVD Description

n8n versions before 1.123.73, 2.35.4, and 2.36.2 contain a remote code execution vulnerability in the Git node. The node reset a fixed list of command-bearing configuration keys before each operation, but that list did not cover the content-filter and merge-driver key families. A repository with local configuration setting one of those keys together with a matching attribute pattern causes git to execute the configured command during an ordinary Add, Commit, Checkout, or Pull operation. The command runs as the n8n process user.

Related CVEs

Other vulnerabilities affecting the same vendor(s)