LOWVulnerability

CVE-2026-72767

n8n before 1.123.67, 2.x before 2.31.5, and 2.32.x before 2.32.1 contain a remote code execution vulnerability in the Git node. Authenticated users with rights to create and execute workflows can stage a crafted local repository that causes git to run hooks under default git security settings, executing arbitrary commands as the n8n process user. Both self-hosted and cloud instances are affected.

Properties

epss_score
0.00387
cve_id
CVE-2026-72767
published_at
2026-08-11T13:19:06.940
last_modified
2026-09-09T20:24:29.453
epss_percentile
0.32136

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72767 — Ninja Signal Threat Intelligence | Ninja Signal