Remote Code Execution Vulnerability in n8n Workflow Automation Platform
CVE-2026-86995
5.3MEDIUM
What is CVE-2026-86995?
The n8n workflow automation platform contains a vulnerability in its Git node, allowing unauthorized access to local repositories. Prior to versions 1.123.76, 2.37.7, and 2.38.2, the platform failed to validate the repository parameter during certain operations. This oversight permitted an authenticated workflow editor to configure the branch..remote setting improperly, leading to unintended access to local repositories accessible by the n8n process. It is crucial for users to upgrade to the specified versions to mitigate potential risks associated with this flaw.
Affected Version(s)
n8n >= 2.38.0, < 2.38.2 < 2.38.0, 2.38.2
n8n >= 2.0.0, < 2.37.7 < 2.0.0, 2.37.7
n8n < 1.123.76 < 1.123.76
