{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-versions-prior-to-2.31.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n versions prior to 1.123.67","n8n versions prior to 2.32.1","n8n versions prior to 2.31.5"],"_cs_severities":["high"],"_cs_tags":["authenticated-rce","workflow-automation","vulnerability"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eThe Canadian Centre for Cyber Security (CCCS) has issued an advisory regarding an authenticated code execution vulnerability (GHSA-rcv6-pvrj-4xcg) affecting the n8n workflow automation platform. Specifically, this flaw resides in the n8n Git node and impacts versions prior to 1.123.67, 2.32.1, and 2.31.5. An attacker who has already gained authenticated access to an n8n instance could exploit this vulnerability to execute arbitrary code on the underlying server. Given n8n's function in automating various tasks and integrating disparate systems, a successful compromise could lead to significant unauthorized access to data, system control, or disruption of critical business operations. Organizations leveraging vulnerable n8n versions are strongly advised to apply the recommended updates immediately to mitigate this risk.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker obtains valid authentication credentials for an n8n instance, either through brute-force, phishing, or other means.\u003c/li\u003e\n\u003cli\u003eThe authenticated attacker then accesses the n8n web interface to create or modify an existing workflow.\u003c/li\u003e\n\u003cli\u003eWithin the workflow editor, the attacker specifically targets and configures an n8n Git node.\u003c/li\u003e\n\u003cli\u003eThe attacker injects malicious commands or code into a parameter or field within the Git node's configuration that is not properly sanitized.\u003c/li\u003e\n\u003cli\u003eWhen the workflow containing the malicious Git node configuration is executed, the injected commands are processed and executed by the underlying operating system with the privileges of the n8n application.\u003c/li\u003e\n\u003cli\u003eThis successful execution allows the attacker to achieve arbitrary code execution on the host server, enabling potential data exfiltration, further system compromise, or deployment of additional malware.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eA successful exploitation of this authenticated code execution vulnerability grants an attacker the ability to run arbitrary commands on the server hosting the n8n instance. This level of access can lead to severe consequences, including full compromise of the n8n application and its data, unauthorized access to sensitive information flowing through integrated workflows, modification or deletion of critical business data, and disruption of automated processes. Furthermore, an attacker could leverage this initial foothold for lateral movement within the network, potentially compromising other systems and expanding the scope of the breach.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eApply Patches\u003c/strong\u003e: Immediately upgrade all affected n8n instances to version 1.123.67, 2.32.1, or 2.31.5, or a newer stable release. This directly remediates the authenticated code execution vulnerability (GHSA-rcv6-pvrj-4xcg).\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eReview Advisories\u003c/strong\u003e: Consult the n8n security advisories (available via the references section) for any additional mitigation steps or specific configuration changes recommended by the vendor.\u003c/li\u003e\n\u003cli\u003e\u003cstrong\u003eLog Monitoring\u003c/strong\u003e: Enable robust process creation and network connection logging on the host system running n8n. Monitor these logs for any unusual or unauthorized processes launched by the n8n application's user account, or unexpected outbound network connections originating from n8n.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T18:08:49Z","date_published":"2026-07-22T18:08:49Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-auth-rce/","summary":"A security advisory from CCCS highlights an authenticated code execution vulnerability (GHSA-rcv6-pvrj-4xcg) within the n8n Git node, affecting multiple versions prior to 1.123.67, 2.32.1, and 2.31.5, which could allow an authenticated attacker to execute arbitrary code on the host system.","title":"n8n Authenticated Code Execution Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-auth-rce/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n Versions Prior to 2.31.5","version":"https://jsonfeed.org/version/1.1"}