CVE-2026-65598: n8n

High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.

n8n before 1.123.64, 2.29.8, and 2.30.1 contains a TOCTOU race condition in the Git node's clone operation that allows authenticated users to bypass path restrictions by swapping a directory for a symlink after the path is validated but before the clone runs. This lets an attacker plant a crafted repository in the community node directory, which n8n loads as a custom node on the next restart, executing arbitrary JavaScript on the server. Both self-hosted and cloud instances are affected.

Affected products

  • n8n n8n: before 1.123.64 (fixed in 1.123.64); from 2.0.0, before 2.29.8 (fixed in 2.29.8); version 2.30.0 only

Published 2026-07-22. Last modified 2026-07-27.