CVE-2026-33724: 
NixOS vulnerability analysis and mitigation

Overview

CVE-2026-33724 is a man-in-the-middle (MITM) vulnerability in n8n, an open-source workflow automation platform, caused by the Source Control feature explicitly disabling SSH host key verification (StrictHostKeyChecking=no) during git operations. This allows a network attacker positioned between the n8n instance and the remote Git server to intercept the connection and present a fraudulent host key. The vulnerability affects all n8n versions prior to 2.5.0 and was disclosed on March 25, 2026. It carries a CVSS v3.1 score of 7.4 (High) and a CVSS v4.0 score of 6.3 (Moderate) (GitHub Advisory, n8n Security Advisory).

Technical details

The root cause is classified as CWE-639 (Authorization Bypass Through User-Controlled Key): the SSH command invoked for git operations in n8n's Source Control feature was hardcoded with StrictHostKeyChecking=no, effectively disabling SSH host key verification entirely. This misconfiguration means the n8n client will accept any host key presented during the SSH handshake, making it trivially susceptible to MITM attacks. Exploitation requires the attacker to be network-adjacent (on the path between the n8n instance and the Git server) and the Source Control feature to be explicitly enabled and configured for SSH — a non-default configuration. No public proof-of-concept code has been identified (GitHub Advisory, n8n Security Advisory).

Impact

A successful exploit allows a network attacker to intercept SSH-based git communications between n8n and the remote Git server, enabling two primary attack outcomes: injection of malicious content into n8n workflows (integrity impact) and interception of sensitive repository data such as credentials, workflow logic, or proprietary automation scripts (confidentiality impact). Availability is not directly impacted. Because n8n workflows can integrate with a wide range of downstream systems and APIs, malicious workflow injection could facilitate lateral movement or further compromise of connected services (GitHub Advisory, n8n Security Advisory).

Exploitability

There is no evidence of active in-the-wild exploitation or a publicly available proof-of-concept as of the time of disclosure. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013–0.017%, placing it in the 4th percentile for exploitation likelihood within 30 days. Exploitation requires a specific non-default configuration (Source Control feature enabled with SSH) and network positioning between the n8n instance and the Git server, which significantly limits the attacker pool (GitHub Advisory, Feedly).

Exploitation steps

  1. Reconnaissance: Identify n8n instances (versions < 2.5.0) that have the Source Control feature enabled and configured to use SSH for Git operations — this is a non-default configuration typically found in enterprise or team deployments.
  2. Network Positioning: Gain a man-in-the-middle position on the network path between the n8n instance and the remote Git server (e.g., via ARP spoofing, DNS poisoning, BGP hijacking, or rogue network device on a shared network segment).
  3. Intercept SSH Handshake: When n8n initiates a git operation (e.g., pull, push, fetch) over SSH, intercept the TCP connection. Because n8n passes StrictHostKeyChecking=no to the SSH command, the client will not verify the server's host key.
  4. Present Fraudulent Host Key: Respond to the SSH handshake with an attacker-controlled host key. The n8n SSH client will accept it without warning or error due to the disabled verification.
  5. Inject or Intercept: Either (a) serve a malicious Git repository containing tampered workflow files that will be pulled into n8n, or (b) passively intercept repository data (workflow definitions, credentials embedded in repos) transmitted during the session (n8n Security Advisory, GitHub Advisory).

Indicators of compromise

  • Network: Unexpected ARP table changes or duplicate MAC addresses on the network segment hosting the n8n instance; anomalous SSH connection attempts or resets between the n8n host and the Git server IP; traffic to unknown IP addresses on port 22 from the n8n host.
  • Logs: SSH client logs (if enabled) showing connections accepted to an unrecognized host key fingerprint; n8n application logs showing unexpected git pull/push operations or errors following a Source Control sync.
  • File System: Unexpected modifications to workflow JSON files in the n8n data directory following a Source Control sync; new or altered workflow files not matching the expected Git repository state.
  • Process: Unusual child processes spawned by the n8n Node.js process related to git or SSH operations at unexpected times; git operations completing without the expected host key warning that would normally appear if verification were enabled.

Mitigation and workarounds

The vulnerability is fixed in n8n version 2.5.0; all users should upgrade immediately. For those unable to upgrade right away, two temporary mitigations are recommended: (1) disable the Source Control feature entirely if it is not actively required, and (2) restrict network access so that the n8n instance can only communicate with the Git server over trusted, controlled network paths (e.g., private VLANs, VPN tunnels, or firewall rules). Note that these workarounds do not fully remediate the risk and should only be used as short-term measures until upgrading is possible (n8n Security Advisory, GitHub Advisory).

Community reactions

The advisory was published by n8n maintainer "Jubke" on March 25, 2026, with credit to reporter "kolega-ai-dev" for discovering the issue. The vulnerability received standard automated coverage from vulnerability tracking services (VulnDB, CVEFeed, CIRCL, ENISA EUVD) shortly after disclosure. No notable independent researcher commentary, media coverage, or significant social media discussion beyond automated CVE tracking posts has been identified (n8n Security Advisory).

Additional resources


Source: This report was generated using AI

Related NixOS vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-103678HIGH8.1
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103680MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103679MEDIUM6.5
  • NixOS logoNixOS
  • tnef
NoNoOct 01, 2026
CVE-2026-103497MEDIUM5.5
  • YouTrack logoYouTrack
  • cpe:2.3:a:jetbrains:youtrack
NoYesOct 01, 2026
CVE-2026-103496MEDIUM5.4
  • YouTrack logoYouTrack
  • youtrack
NoYesOct 01, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management