CVE-2026-33724Disclosure(n8n / n8n)

LOWCVSS 7.4 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git operations explicitly disabled host key verification. A network attacker positioned between the n8n instance and the remote Git server could intercept the connection and present a fraudulent host key, potentially injecting malicious content into workflows or intercepting repository data. This issue only affects instances where the Source Control feature has been explicitly enabled and configured to use SSH (non-default). The issue has been fixed in n8n version 2.5.0. Users should upgrade to this version or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should consider the following temporary mitigations: Disable the Source Control feature if it is not actively required, and/or restrict network access to ensure the n8n instance communicates with the Git server only over trusted, controlled network paths. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-639

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
n8n

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-25: 2Patch / Workaround · 2026-03-25: 1Technical Details · 2026-03-25: 203-25
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
By indicator
Full discourse2 posts
  • CVE@CVEnew
    Disclosure

    CVE-2026-33724 n8n is an open source workflow automation platform. Prior to version 2.5.0, when the Source Control feature is configured to use SSH, the SSH command used for git ope… https://www.cve.org/CVERecord?id=CVE-2026-33724

    Post summary

    CVE‑2026‑33724 affects the n8n workflow platform’s Source Control SSH functionality before version 2.5.0; no PoC, exploit, or active exploitation is reported, but upgrading to 2.5.0 mitigates the issue.

    10010126
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-33724 - n8n's Source Control SSH Configuration Uses StrictHostKeyChecking=no Intel Report: https://ift.tt/cM3Csv5

    Post summary

    The alert announces CVE-2026-33724, pointing out a misconfigured SSH setting in n8n's source control that could pose a security risk. No PoC, exploit, active exploitation, or remediation details are provided.

    0000027
    286 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-

Explore more