CVE-2026-65598Disclosure(n8n / n8n)

LOWCVSS 7.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-367

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • Disclosure: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-08-18: 1Patch / Workaround · 2026-08-18: 1Technical Details · 2026-08-18: 108-18
Signal classification1 categories
Disclosure
1100.0%
Full discourse1 post
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨High - n8n Git node clone TOCTOU race → authenticated RCE (CVE-2026-65598 / GHSA-g3r5-9h93-4j2c) A TOCTOU race in the Git node's clone lets an authenticated workflow user swap a validated directory for a symlink before the clone runs, planting a crafted repo in the community node directory — n8n loads it as a custom node on restart and executes its JavaScript on the server. Self-hosted and cloud both affected. 👉Affected: n8n < 1.123.64, < 2.29.8, < 2.30.1 | Upgrade to 1.123.64 / 2.29.8 / 2.30.1. Interim: NODES_EXCLUDE=n8n-nodes-base.git

    Post summary

    The post announces a high‑severity CVE-2026-65598 in n8n’s Git node clone, describing a TOCTOU race that leads to authenticated RCE, and recommends upgrades to mitigate the vulnerability.

    0001091
    291 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n-node.js-
Appn8nn8n2.30.0node.js-
Appn8nn8n2.30.0node.js-

Explore more