CVE-2025-62726
HIGHDescription
n8n is an open source workflow automation platform. Prior to 1.113.0, a remote code execution vulnerability exists in the Git Node component available in both Cloud and Self-Hosted versions of n8n. When a malicious actor clones a remote repository containing a pre-commit hook, the subsequent use of the Commit operation in the Git Node can inadvertently trigger the hook’s execution. This allows attackers to execute arbitrary code within the n8n environment, potentially compromising the system and any connected credentials or workflows. This vulnerability is fixed in 1.113.0.
Is your site exposed to CVE-2025-62726?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| n8n | n8n |
References
Frequently Asked Questions
What is CVE-2025-62726? +
How severe is CVE-2025-62726? +
What products are affected by CVE-2025-62726? +
How do I check if I'm vulnerable to CVE-2025-62726? +
Related Vulnerabilities
PDM is a Python package and dependency manager. In versions up to and including 2.26.9, PDM automatically loads project-local plugins …
Cursor is a code editor built for programming with AI. In versions prior to 3.0.0, the Cursor Desktop could execute …
MyBooks is an enhanced and easy-to-use personal ebook management web server also known as Talebook. In 3.41.2 and earlier, the …
In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The …
Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.3, the repository …
Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, `kiota info` read x-ms-kiota-info.languagesInformation.<language>.dependencyInstallCommand plus dependency name and …