CVE-2026-65598: Time-of-check Time-of-use (TOCTOU) Race Condition in n8n-io n8n
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.
AI Analysis
Technical Summary
The vulnerability CVE-2026-65598 in n8n involves a TOCTOU race condition in the Git node's clone operation. Authenticated users can bypass path restrictions by replacing a directory with a symbolic link after the path check but before the clone operation executes. This enables planting a crafted repository in the community node directory, which n8n loads as a custom node upon restart, resulting in arbitrary JavaScript code execution on the server. This affects versions prior to 1.123.64, 2.29.8, and 2.30.1. The vulnerability has a CVSS 4.0 score of 8.9, indicating high severity. Both self-hosted and cloud deployments are impacted, though this instance is not a cloud service and no official remediation level or patch links are provided.
Potential Impact
Successful exploitation allows an authenticated attacker to bypass path restrictions and execute arbitrary JavaScript code on the server by planting a malicious repository that n8n loads as a custom node. This can lead to server compromise and unauthorized code execution. The vulnerability affects both self-hosted and cloud instances of n8n.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided and the remediation level is null, users should monitor the vendor's advisories closely. Until a patch is available, restrict authenticated user permissions to trusted individuals only and consider limiting access to the Git node functionality to mitigate risk.
CVE-2026-65598: Time-of-check Time-of-use (TOCTOU) Race Condition in n8n-io n8n
Description
n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.
CVSS v4.0
Score 8.9high
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability CVE-2026-65598 in n8n involves a TOCTOU race condition in the Git node's clone operation. Authenticated users can bypass path restrictions by replacing a directory with a symbolic link after the path check but before the clone operation executes. This enables planting a crafted repository in the community node directory, which n8n loads as a custom node upon restart, resulting in arbitrary JavaScript code execution on the server. This affects versions prior to 1.123.64, 2.29.8, and 2.30.1. The vulnerability has a CVSS 4.0 score of 8.9, indicating high severity. Both self-hosted and cloud deployments are impacted, though this instance is not a cloud service and no official remediation level or patch links are provided.
Potential Impact
Successful exploitation allows an authenticated attacker to bypass path restrictions and execute arbitrary JavaScript code on the server by planting a malicious repository that n8n loads as a custom node. This can lead to server compromise and unauthorized code execution. The vulnerability affects both self-hosted and cloud instances of n8n.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since no official fix or patch links are provided and the remediation level is null, users should monitor the vendor's advisories closely. Until a patch is available, restrict authenticated user permissions to trusted individuals only and consider limiting access to the Git node functionality to mitigate risk.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2026-07-22T10:45:44.833Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a60ab939c2644c7f8eced4d
Added to database: 07/22/2026, 11:37:55 UTC
Last enriched: 07/22/2026, 11:52:05 UTC
Last updated: 07/23/2026, 02:51:54 UTC
Views: 14
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.