n8n-io has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 5.0 (medium).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 5.0
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Weakness classes
Products
- n8n 3
n8n-io vulnerabilities
CVEs affecting n8n-io, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-92587Medium· 5.0n8n is a workflow automation platform
n8n is a workflow automation platform. In versions before 1.123.76, 2.37.7, and 2.38.2, the Git node validated a relative remote URL against the configured repositoryPath but then invoked git with that path as its working directory; git …
CVE-2026-92588Medium· 4.4n8n is a workflow automation platform
n8n is a workflow automation platform. In n8n versions before 1.123.76, 2.37.7, and 2.38.2, the source control push endpoint derived the set of files to push from the file paths and status supplied in the client request payload instead o…
CVE-2026-86081High· 7.1n8n is an open source workflow automation platform
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The p…