CVE-2026-49465Medium· 7.7▾ Sunlitn8n: Git Node Clone and Push Operations Bypass File Sandbox
▾ Sunlit zone — Low / medium · no exploitation signal
impact 42.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 4.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.5%
0.5% → 0.5%
An authenticated user with permission to create or modify workflows could supply a local filesystem path as the source repository in the Git node's Clone operation, or as the target repository in the Push operation, bypassing the N8N_RESTRICT_FILE_ACCESS_TO file sandbox. This allowed the contents of any local git repository accessible to the n8n process to be cloned into an allowed path and read, circumventing the access restrictions that correctly blocked direct file reads to the same paths.
The issue has been fixed in n8n versions 1.123.48, 2.21.8, and 2.22.4. Users should upgrade to one of these versions or later to remediate the vulnerability.
If upgrading is not immediately possible, administrators should consider the following temporary mitigations:
n8n-nodes-base.git to the NODES_EXCLUDE environment variable.These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.
n8n < 1.123.48n8n >= 2.22.0, < 2.22.4n8n >= 2.0.0-rc.0, < 2.21.8Upgrade to a patched release:
n8n 1.123.48n8n 2.22.4n8n 2.21.8Connected by shared product, vendor, weakness, or advisory.
CVE-2026-86079Medium· 6.5n8n is an open source workflow automation platform
GHSA-gf29-4f56-r2jfHighn8n: Git Node fetch/pull/pushTags Operations Bypass Sandbox Path Restriction
GHSA-pf2q-pxhf-hgmwMediumn8n: Path-Confinement Bypass in computer-use search_files Allows Reading Files Outside the Base Directory
CVE-2026-86995Medium· 4.3n8n is an open source workflow automation platform
CVE-2026-86083High· 8.8n8n is an open source workflow automation platform
CVE-2026-86084Medium· 5.5n8n is an open source workflow automation platform