A critical remote code execution (RCE) vulnerability, tracked as CVE-2025-65964, has been identified in the workflow automation tool n8n. The flaw allows attackers to achieve RCE by manipulating the Git node's custom pre-commit hook configuration, potentially enabling unauthorized access and control over affected systems. Security advisories highlight the severity of this issue, with a CVSS 4.0 score of 9.4, categorizing it as critical and emphasizing the urgent need for remediation.
The vulnerability exposes organizations using n8n to significant risk, as exploitation could lead to full system compromise. Administrators are strongly advised to review their deployments, apply available patches, and monitor for any signs of unauthorized activity related to Git node configurations. No evidence of active exploitation has been reported as of the latest advisories, but the technical nature of the flaw and its critical rating warrant immediate attention from security teams.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A critical remote code execution vulnerability, CVE-2025-65964, was disclosed in n8n. The flaw affects the Git node's custom pre-commit hook or configuration handling and could allow attackers to execute arbitrary code on affected systems.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
securityonline.info
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.