n8n, Remote Code Execution, CVE-2024-53717 (Critical)

Listen to this Post

The CVE-2024-53717 vulnerability exploits the trust model of Git hooks within n8n’s Git Node. When the Git Node clones a repository, it creates a standard working directory. A malicious actor can craft a repository containing a malicious `pre-commit` hook script. This hook is placed in the `.git/hooks/` directory. By design, Git will execute this script during a commit operation if the hook has executable permissions. The n8n Git Node’s “Commit” operation triggers this standard Git behavior. Since n8n executes the Git operations in a context with sufficient system privileges, the malicious script runs with the same permissions as the n8n process. This allows an attacker to run any system command, leading to full remote code execution on the n8n server, compromising the entire instance and any stored credentials or data.
Platform: n8n
Version: <1.113.0
Vulnerability: RCE
Severity: Critical
date: 2024

Prediction: 2024-10-15

What Undercode Say:

`find / -name “pre-commit” -path “/.git/hooks/” 2>/dev/null`

`chmod -x .git/hooks/`

`export N8N_GIT_NODE_DISABLE_BARE_REPOS=true`

How Exploit:

Malicious repo clone.

Git hook execution.

Arbitrary code runs.

Protection from this CVE

Upgrade to v1.113.0.

Set environment variable.

Avoid untrusted repositories.

Impact:

Full system compromise.

Credential theft.

Workflow manipulation.

🎯Let’s Practice Exploiting & Learn Patching For Free:

Sources:

Reported By: github.com
Extra Source Hub:
Undercode

🔐JOIN OUR CYBER WORLD [ CVE News • HackMonitor • UndercodeNews ]

💬 Whatsapp | 💬 Telegram

📢 Follow DailyCVE & Stay Tuned:

𝕏 formerly Twitter 🐦 | @ Threads | 🔗 Linkedin Featured Image

Scroll to Top