{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/products/n8n-vulnerable-versions--2.32.0--2.32.1/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["n8n (Vulnerable versions: \u003c 1.123.67)","n8n (Vulnerable versions: \u003e= 2.0.0-rc.0, \u003c 2.31.5)","n8n (Vulnerable versions: \u003e= 2.32.0, \u003c 2.32.1)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","sandbox-bypass","n8n","data-exfiltration","workflow-automation"],"_cs_type":"advisory","_cs_vendors":["n8n GmbH"],"content_html":"\u003cp\u003eA high-severity vulnerability has been identified in the n8n workflow automation platform that allows authenticated users to bypass intended sandbox path restrictions. This vulnerability affects n8n versions prior to 1.123.67, versions from 2.0.0-rc.0 to below 2.31.5, and version 2.32.0. The flaw resides within the Git node's \u003ccode\u003efetch\u003c/code\u003e, \u003ccode\u003epull\u003c/code\u003e, and \u003ccode\u003epush-tags\u003c/code\u003e operations, which can be manipulated by an attacker to point an allowlisted remote configuration value at a local path outside the designated sandbox. This allows the attacker to pull arbitrary local Git repositories into the n8n workspace, subsequently exposing their files and history. This issue is critical for organizations using n8n, as it could lead to unauthorized access and exfiltration of sensitive source code or other local system data from the host running the n8n instance.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn attacker gains authenticated access to an n8n instance with workflow creation and execution rights.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts a new n8n workflow or modifies an existing one.\u003c/li\u003e\n\u003cli\u003eWithin the workflow, the attacker adds or configures a Git node to perform \u003ccode\u003efetch\u003c/code\u003e, \u003ccode\u003epull\u003c/code\u003e, or \u003ccode\u003epush-tags\u003c/code\u003e operations.\u003c/li\u003e\n\u003cli\u003eThe attacker manipulates the Git node's configuration by setting an allowlisted remote configuration value to a local file path that lies outside n8n's intended sandbox.\u003c/li\u003e\n\u003cli\u003eThe attacker executes the maliciously configured n8n workflow.\u003c/li\u003e\n\u003cli\u003eDuring execution, the Git node, using the manipulated remote configuration, bypasses the internal repository-path containment checks.\u003c/li\u003e\n\u003cli\u003eThe n8n instance pulls an arbitrary local Git repository from the host system into its workspace, effectively making its contents accessible within the n8n environment.\u003c/li\u003e\n\u003cli\u003eThe attacker can then access and read the files and historical data contained within the exposed local Git repository, leading to data collection.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe successful exploitation of this vulnerability by an authenticated n8n user can lead to the unauthorized disclosure of sensitive information. Attackers can access and read the contents, including source code and historical data, of any local Git repository present on the n8n host system that they manage to pull into the workspace. This could expose intellectual property, credentials, internal system configurations, and other proprietary data. While no specific victim count or sectors are mentioned, any organization using affected versions of n8n is at risk of significant data exfiltration if the n8n host contains valuable Git repositories.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade n8n instances to versions 1.123.67, 2.31.5, 2.32.1, or later immediately as outlined in the \u003ccode\u003ePatches\u003c/code\u003e section of the advisory.\u003c/li\u003e\n\u003cli\u003eRestrict n8n instance access to fully trusted users only to mitigate risks while awaiting upgrades, as specified in the \u003ccode\u003eWorkarounds\u003c/code\u003e section.\u003c/li\u003e\n\u003cli\u003eDisable the Git node by adding \u003ccode\u003en8n-nodes-base.git\u003c/code\u003e to the \u003ccode\u003eNODES_EXCLUDE\u003c/code\u003e environment variable if immediate upgrade is not possible, as detailed in the \u003ccode\u003eWorkarounds\u003c/code\u003e section.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-22T22:10:53Z","date_published":"2026-07-22T22:10:53Z","id":"https://feed.craftedsignal.io/briefs/2026-07-n8n-git-node-sandbox-bypass/","summary":"An authenticated n8n user can exploit a path restriction bypass vulnerability within the Git node's fetch, pull, or push-tags operations to access arbitrary local Git repositories and their contents, potentially leading to sensitive data exposure.","title":"n8n Git Node Operations Bypass Sandbox Path Restriction","url":"https://feed.craftedsignal.io/briefs/2026-07-n8n-git-node-sandbox-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - N8n (Vulnerable Versions: \u003e= 2.32.0, \u003c 2.32.1)","version":"https://jsonfeed.org/version/1.1"}