Security Vulnerability in n8n Workflow Automation Platform
CVE-2026-86081
7.1HIGH
What is CVE-2026-86081?
n8n is an open source workflow automation platform that experienced a vulnerability in its Git node clone operation. Versions prior to 1.123.76, 2.37.7, and 2.38.2 suffered from a flaw where an attacker could exploit the destination path validation against the default N8N_BLOCK_FILE_PATTERNS regular expression. This vulnerability allowed for catastrophic backtracking, effectively freezing the n8n instance during workflow execution when an authenticated workflow editor triggered the attack. The critical configuration issue was addressed in subsequent software updates, ensuring better protection for users.
Affected Version(s)
n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2
n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7
n8n < 1.123.76 < 1.123.76
