CVE-2026-71539 - n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution
Brief
CVE ID : CVE-2026-71539
Published : Aug. 18, 2026, 2:43 p. m.
- 24 minutes ago
Description : n8n is an open source workflow automation platform. Prior to 1.
- 64, 2.
- 8, and 2.
- 1, the Git node clone operation allows an authenticated workflow user to swap a validated directory for a symlink before cloning, planting a crafted repository in the community node directory that loads as a custom JavaScript node after restart and executes arbitrary code on the server.
This issue is fixed in versions 1.
- 64, 2.
- 8, and 2.
- 1.
Severity: 0.0
- NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
