logo

Warning: Remote Code Execution in n8n project, Patch Immediately!

ID: 007387a0-3051-5414-928d-da0e98b57c5d

STIX ID: report--007387a0-3051-5414-928d-da0e98b57c5d

Feed Name: CCB Advisories Feed

Threat Score
75/100

Date Published: 2025-12-09

Date Updated: 2026-07-24

...
...

A critical RCE vulnerability (CVE-2025-65964, CVSS 9.4) in the n8n Git node permits authenticated workflow editors to set core.hooksPath via the "Add Config" function, enabling execution of malicious Git hooks during operations and potential host compromise; affected versions are listed and the issue is fixed in n8n 1.119.2. Immediate mitigation advises patching, disabling the Git node or restricting workflow editing to trusted admins, and increasing monitoring for suspicious activity.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.