Security Vulnerability in n8n Workflow Automation Platform
CVE-2026-86081

7.1HIGH

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86081?

n8n is an open source workflow automation platform that experienced a vulnerability in its Git node clone operation. Versions prior to 1.123.76, 2.37.7, and 2.38.2 suffered from a flaw where an attacker could exploit the destination path validation against the default N8N_BLOCK_FILE_PATTERNS regular expression. This vulnerability allowed for catastrophic backtracking, effectively freezing the n8n instance during workflow execution when an authenticated workflow editor triggered the attack. The critical configuration issue was addressed in subsequent software updates, ensuring better protection for users.

Affected Version(s)

n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2

n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7

n8n < 1.123.76 < 1.123.76

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.