Remote Code Execution Vulnerability in n8n Workflow Automation Platform
CVE-2026-86995

5.3MEDIUM

Key Information:

Vendor

N8n-io

Status
Vendor
CVE Published:
8 September 2026

What is CVE-2026-86995?

The n8n workflow automation platform contains a vulnerability in its Git node, allowing unauthorized access to local repositories. Prior to versions 1.123.76, 2.37.7, and 2.38.2, the platform failed to validate the repository parameter during certain operations. This oversight permitted an authenticated workflow editor to configure the branch..remote setting improperly, leading to unintended access to local repositories accessible by the n8n process. It is crucial for users to upgrade to the specified versions to mitigate potential risks associated with this flaw.

Affected Version(s)

n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2

n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7

n8n < 1.123.76 < 1.123.76

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.