Skip to content
n8nGHSA-5xp3-2w67-427v

n8n: Git Node Clone and Push Operations Bypass File Sandbox

Medium7.7CVE-2026-49465 · Published Jun 16, 2026 · updated Jul 20, 2026

## Impact An authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone operation, or as the target repository in the Push operation, bypassing the `N8N_RESTRICT_FILE_ACCESS_TO` file sandbox. This allowed the contents of any local git repository accessible to the n8n process to be cloned into an allowed path and read, circumventing the access restrictions that correctly blocked direct file reads to the same paths. ## Patches The issue has been fixed in n8n versions 1.123.48, 2.21.8, and 2.22.4. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Limit workflow creation and editing permissions to fully trusted users only. - Disable the Git node by adding `n8n-nodes-base.git` to the `NODES_EXCLUDE` environment variable. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

GitHub advisory

Affected versions

PackageAffectedFixed in
n8n
npm
< 1.123.481.123.48
>= 2.22.0, < 2.22.42.22.4
>= 2.0.0-rc.0, < 2.21.82.21.8
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-22
Also known as
CVE-2026-49465

More n8n advisories

All n8n
Advisory
n8n: SecurityScorecard Node Leaks API Token to User-Controlled Host
High7.7Jun 16
n8n: MCP Browser HTTP Transport Exposes Unauthenticated Browser-Control Sessions
High10.0Jun 16
n8n: Cross-Tenant Credential Takeover via Dynamic Credentials EE Endpoints
High9.9Jun 16
n8n: Credential Exfiltration via Permission Bypass
High9.6Jun 16
n8n: Denial of Service via ZIP decompression in webhook workflow
Medium5.9Jun 16
n8n: Public API Execution Retry Authorization Bypass
Medium6.4Jun 16

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.