
🚨High - n8n Git node clone TOCTOU race → authenticated RCE (CVE-2026-65598 / GHSA-g3r5-9h93-4j2c) A TOCTOU race in the Git node's clone lets an authenticated workflow user swap a validated directory for a symlink before the clone runs, planting a crafted repo in the community node directory — n8n loads it as a custom node on restart and executes its JavaScript on the server. Self-hosted and cloud both affected. 👉Affected: n8n < 1.123.64, < 2.29.8, < 2.30.1 | Upgrade to 1.123.64 / 2.29.8 / 2.30.1. Interim: NODES_EXCLUDE=n8n-nodes-base.git
Post summary
The post announces a high‑severity CVE-2026-65598 in n8n’s Git node clone, describing a TOCTOU race that leads to authenticated RCE, and recommends upgrades to mitigate the vulnerability.
