THREAT OPS › Threat News › [GHSA] GHSA-qgpw-8g46-w95v (medium) — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
[GHSA] GHSA-qgpw-8g46-w95v (medium) — n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
GHSA-qgpw-8g46-w95v Severity: medium CVE: CVE-2026-86995
n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
## Impact
The Git node validated the repository that a fetch or pull targeted, but `setUpstream` wrote a `branch.<name>.remote` value into the repository's own configuration without validating it. A subsequent fetch or pull
Indicators of compromise
- CVE-2026-86995cve
Original source: https://github.com/advisories/GHSA-qgpw-8g46-w95v