
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-33724 is a man-in-the-middle (MITM) vulnerability in n8n, an open-source workflow automation platform, caused by the Source Control feature explicitly disabling SSH host key verification (StrictHostKeyChecking=no) during git operations. This allows a network attacker positioned between the n8n instance and the remote Git server to intercept the connection and present a fraudulent host key. The vulnerability affects all n8n versions prior to 2.5.0 and was disclosed on March 25, 2026. It carries a CVSS v3.1 score of 7.4 (High) and a CVSS v4.0 score of 6.3 (Moderate) (GitHub Advisory, n8n Security Advisory).
The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the SSH command invoked for git operations in n8n's Source Control feature was hardcoded with StrictHostKeyChecking=no, effectively disabling SSH host key verification entirely. This misconfiguration means the n8n client will accept any host key presented during the SSH handshake, making it trivially susceptible to MITM attacks. Exploitation requires the attacker to be network-adjacent (on the path between the n8n instance and the Git server) and the Source Control feature to be explicitly enabled and configured for SSH — a non-default configuration. No public proof-of-concept code has been identified (GitHub Advisory, n8n Security Advisory).
A successful exploit allows a network attacker to intercept SSH-based git communications between n8n and the remote Git server, enabling two primary attack outcomes: injection of malicious content into n8n workflows (integrity impact) and interception of sensitive repository data such as credentials, workflow logic, or proprietary automation scripts (confidentiality impact). Availability is not directly impacted. Because n8n workflows can integrate with a wide range of downstream systems and APIs, malicious workflow injection could facilitate lateral movement or further compromise of connected services (GitHub Advisory, n8n Security Advisory).
There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013–0.017%, placing it in the 4th percentile for exploitation likelihood within 30 days. Exploitation requires a specific non-default configuration (Source Control feature enabled with SSH) and network positioning between the n8n instance and the Git server, which significantly limits the attacker pool (GitHub Advisory, Feedly).
StrictHostKeyChecking=no to the SSH command, the client will not verify the server's host key.The vulnerability is fixed in n8n version 2.5.0; all users should upgrade immediately. For those unable to upgrade right away, two temporary mitigations are recommended: (1) disable the Source Control feature entirely if it is not actively required, and (2) restrict network access so that the n8n instance can only communicate with the Git server over trusted, controlled network paths (e.g., private VLANs, VPN tunnels, or firewall rules). Note that these workarounds do not fully remediate the risk and should only be used as short-term measures until upgrading is possible (n8n Security Advisory, GitHub Advisory).
The advisory was published by n8n maintainer "Jubke" on March 25, 2026, with credit to reporter "kolega-ai-dev" for discovering the issue. The vulnerability received standard automated coverage from vulnerability tracking services (VulnDB, CVEFeed, CIRCL, ENISA EUVD) shortly after disclosure. No notable independent researcher commentary, media coverage, or significant social media discussion beyond automated CVE tracking posts has been identified (n8n Security Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."