Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 2

Количество 2

nvd логотип

CVE-2026-65598

17 дней назад

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-g3r5-9h93-4j2c

17 дней назад

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-65598

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.

CVSS3: 7.5
0%
Низкий
17 дней назад
github логотип
GHSA-g3r5-9h93-4j2c

n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution

0%
Низкий
17 дней назад

Уязвимостей на страницу