n8n disclosed multiple high-severity vulnerabilities affecting the workflow automation platform, including an authentication bypass, security restrictions bypass, arbitrary file read and write, denial of service, and a remote code execution flaw in the Git node. The issues affect 1.x versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1, with exposure spanning both self-hosted and cloud deployments.
The Git node vulnerability allows an authenticated user with permission to create and run workflows to prepare a crafted local repository that triggers Git hooks under default Git security settings, leading to arbitrary command execution as the n8n process user. Italy's national CSIRT said the vendor has published security guidance and urged organizations running affected versions to apply the recommended mitigations and updates.

See affected versions and whether adversaries are exploiting it.
3 events from the most recent confirmed update back to the earliest known activity.
A high-severity vulnerability in n8n's Send Email node, tracked as CVE-2026-72766, was disclosed affecting versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. The type confusion flaw can cause Nodemailer to treat crafted body-field input as a file path or URL, enabling arbitrary local file disclosure and SSRF under specific non-default conditions.
A remote code execution flaw in the n8n Git node was documented for versions before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1. The vulnerability allows an authenticated user with workflow creation and execution rights to prepare a crafted local repository that triggers Git hooks and executes arbitrary commands as the n8n process user.
The n8n-io development team identified and disclosed several high-severity vulnerabilities in n8n, including authentication bypass, security restrictions bypass, arbitrary file read/write, arbitrary code execution, and denial of service. The issues affect n8n 1.x before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
acn.gov.it
Open sourcecvefeed.io
Open sourcevulncheck.com
Open sourcevulncheck.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.