Impact
n8n implements a Git node clone that validates the destination path against a regular expression pattern in the default blocked‑file list. The pattern ^(./).git(/.)$ is vulnerable to catastrophic backtracking and executes synchronously on the main n8n process. Triggering the match on a crafted path causes the pattern engine to explore an exponential number of possibilities, effectively blocking or severely degrading the service for the duration of the match. The vulnerability is a classic Regular Expression Denial of Service (CWE‑1333).
Affected Systems
The issue affects the open‑source workflow automation platform n8n from the vendor n8n‑io. All releases prior to 1.123.76, 2.37.7, and 2.38.2 are impacted. Upgrading to any of those patched versions or later removes the vulnerable match logic and restores normal operation.
Risk and Exploitability
The CVSS score is 7.1, indicating a medium to high severity. EPSS is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA Knowledge Exploited Vulnerabilities catalog. The only known way to trigger the denial is by executing a workflow that utilizes the Git node with a destination path under the control of an authenticated workflow editor. Based on the description, the attack vector is inferred to be a privileged internal user who can edit or create workflows; no external unauthenticated vector is documented.
OpenCVE Enrichment
Github GHSA