{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-npm/n8n--2.30.0--2.30.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-65598"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (npm/n8n) \u003c 1.123.64","n8n (npm/n8n) \u003e= 2.30.0, \u003c 2.30.1","n8n (npm/n8n) \u003e= 2.0.0-rc.0, \u003c 2.29.8"],"_cs_severities":["high"],"_cs_tags":["race-condition","rce","n8n","cloud","web-application"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity Time-of-Check to Time-of-Use (TOCTOU) race condition, identified as CVE-2026-65598, has been discovered in the Git node functionality of n8n, an open-source workflow automation platform. This vulnerability allows authenticated users to bypass path restrictions during a \u003ccode\u003egit clone\u003c/code\u003e operation. By exploiting the brief window between a directory path's validation and the actual clone execution, an attacker can replace the intended target directory with a symbolic link pointing to the community node directory. This enables the attacker to plant a crafted, malicious repository directly into n8n's custom node directory. Upon the subsequent restart of the n8n server, this malicious repository is loaded as a custom node, granting the attacker arbitrary JavaScript code execution on the underlying server. Both self-hosted and cloud instances of n8n are affected if authenticated users can create and run workflows using the Git node.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated user gains initial access to the n8n instance and creates a workflow containing a Git node.\u003c/li\u003e\n\u003cli\u003eThe attacker configures the Git node to clone a controlled repository, triggering the application's internal path validation logic for the target directory.\u003c/li\u003e\n\u003cli\u003eDuring the time-of-check (path validation) and time-of-use (actual \u003ccode\u003egit clone\u003c/code\u003e execution) window, the attacker races to replace the validated target directory with a symbolic link.\u003c/li\u003e\n\u003cli\u003eThe symbolic link is crafted to point to the n8n \u003ccode\u003ecommunity node directory\u003c/code\u003e, a location where custom nodes are loaded.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003egit clone\u003c/code\u003e operation then proceeds, writing the contents of the attacker-controlled malicious repository into the \u003ccode\u003ecommunity node directory\u003c/code\u003e via the symlink.\u003c/li\u003e\n\u003cli\u003eUpon the next restart of the n8n server process, the newly planted malicious repository is loaded and registered as a custom node.\u003c/li\u003e\n\u003cli\u003eSince n8n executes JavaScript code within custom nodes, the attacker achieves arbitrary code execution on the server.\u003c/li\u003e\n\u003cli\u003eThe final objective is likely full compromise of the n8n server, potentially leading to data exfiltration, further lateral movement, or service disruption.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-65598 results in arbitrary code execution (RCE) on the n8n server. This allows an authenticated attacker to take full control of the underlying host system, impacting both self-hosted and cloud instances of n8n. The attacker can execute any command with the privileges of the n8n service, potentially leading to sensitive data exposure, unauthorized modification of workflows or data, or using the compromised server as a pivot point for further attacks within the organization's network. The extent of damage is critical, as it undermines the integrity and confidentiality of the n8n platform and any integrated systems.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances immediately to a patched version once available to remediate CVE-2026-65598.\u003c/li\u003e\n\u003cli\u003eIf immediate upgrade is not possible, restrict n8n instance access to fully trusted users only to mitigate risks related to authenticated exploitation.\u003c/li\u003e\n\u003cli\u003eAs a temporary measure, disable the Git node functionality by adding \u003ccode\u003en8n-nodes-base.git\u003c/code\u003e to the \u003ccode\u003eNODES_EXCLUDE\u003c/code\u003e environment variable within your n8n environment.\u003c/li\u003e\n\u003cli\u003eRestrict network egress from the n8n instance to prevent connections to arbitrary or attacker-controlled git repositories, reducing the attack surface.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:04:21Z","date_published":"2026-07-22T18:04:21Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-git-node-rce/","summary":"A Time-of-Check to Time-of-Use (TOCTOU) race condition in n8n's Git node allows an authenticated user to achieve remote code execution (RCE) by swapping a directory with a symlink after path validation but before cloning, leading to the loading of a crafted malicious custom node upon server restart.","title":"N8n Git Node Race Condition Allows Authenticated RCE (CVE-2026-65598)","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-git-node-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (Npm/N8n) \u003e= 2.30.0, \u003c 2.30.1","version":"https://jsonfeed.org/version/1.1"}