{"id":"CVE-2026-86081","title":"n8n is an open source workflow automation platform","summary":"n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…","severity":"high","cvss":7.1,"cvssVector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-1333"],"vendor":"n8n-io","product":"n8n","affected":["n8n >= 2.38.0, < 2.38.2","n8n >= 2.0.0, < 2.37.7","n8n < 1.123.76"],"published":"2026-09-08","updated":"2026-09-09","sourceUpdated":"2026-09-09T20:16:54.383","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86081","references":[{"url":"https://github.com/n8n-io/n8n/releases/tag/n8n@1.123.76","label":"security-advisories@github.com"},{"url":"https://github.com/n8n-io/n8n/releases/tag/n8n@2.37.7","label":"security-advisories@github.com"},{"url":"https://github.com/n8n-io/n8n/releases/tag/n8n@2.38.2","label":"security-advisories@github.com"},{"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-j535-v25q-vx3q","label":"security-advisories@github.com"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86081"},{"url":"https://github.com/advisories/GHSA-j535-v25q-vx3q"}],"tags":["nvd","cve.org","ghsa","npm"],"epss":0.0056,"epssPercentile":0.44288,"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-09-09T13:45:20.437735Z"},"cvssSource":"cna","ingestedAt":"2026-09-08T22:12:31.038Z","aliases":["GHSA-j535-v25q-vx3q"],"ecosystem":"npm","patched":["n8n 1.123.76","n8n 2.38.2","n8n 2.37.7"],"slug":"CVE-2026-86081","body":"## Overview\n\nn8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-86081)\n\nAffected packages:\n\n- `n8n < 1.123.76`\n- `n8n >= 2.38.0, < 2.38.2`\n- `n8n >= 2.0.0, < 2.37.7`\n\nPatched in:\n\n- `n8n 1.123.76`\n- `n8n 2.38.2`\n- `n8n 2.37.7`\n\nSource: https://github.com/advisories/GHSA-j535-v25q-vx3q","depth":"twilight","depthScore":39,"depthScoreParts":{"impact":39.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}