Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Patch
AI Analysis

Impact

n8n implements a Git node clone that validates the destination path against a regular expression pattern in the default blocked‑file list. The pattern ^(./).git(/.)$ is vulnerable to catastrophic backtracking and executes synchronously on the main n8n process. Triggering the match on a crafted path causes the pattern engine to explore an exponential number of possibilities, effectively blocking or severely degrading the service for the duration of the match. The vulnerability is a classic Regular Expression Denial of Service (CWE‑1333).

Affected Systems

The issue affects the open‑source workflow automation platform n8n from the vendor n8n‑io. All releases prior to 1.123.76, 2.37.7, and 2.38.2 are impacted. Upgrading to any of those patched versions or later removes the vulnerable match logic and restores normal operation.

Risk and Exploitability

The CVSS score is 7.1, indicating a medium to high severity. EPSS is not available, so the exploitation probability is unknown. The vulnerability is not listed in the CISA Knowledge Exploited Vulnerabilities catalog. The only known way to trigger the denial is by executing a workflow that utilizes the Git node with a destination path under the control of an authenticated workflow editor. Based on the description, the attack vector is inferred to be a privileged internal user who can edit or create workflows; no external unauthenticated vector is documented.

Generated by OpenCVE AI on September 9, 2026 at 08:51 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the n8n 1.123.76 or newer 2.37.7/2.38.2 releases to eliminate the vulnerable regex
  • Verify that the workflow configuration does not re‑introduce the old pattern and that the default blocked‑file patterns are not overridden
  • If the Git node is not required in the environment, disable or remove the node from eligible workflow templates to prevent any future accidental match attempts

Generated by OpenCVE AI on September 9, 2026 at 08:51 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-j535-v25q-vx3q n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
Vendors & Products N8n
N8n n8n

Wed, 09 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Title n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path
Weaknesses CWE-1333
References
Metrics cvssV4_0

{'score': 7.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T13:45:42.273Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86081

cve-icon Vulnrichment

Updated: 2026-09-09T13:45:39.534Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-08T22:19:17.093

Modified: 2026-09-09T20:16:54.383

Link: CVE-2026-86081

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:06Z

Weaknesses
  • CWE-1333

    Inefficient Regular Expression Complexity