CVE-2026-86081: n8n: Regular Expression Denial of Service in the Default Blocked-File-Pattern Match via a Git Node Clone Path

Published Sep 8, 2026
·
Updated

n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8NBLOCKFILEPATTERNS regular expression. The pattern ^(./).git(/.)$ allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.

Affected Software

1 affected component
n8n<1.123.76, >1.123.76<=1.123.76, <2.37.7, <2.38.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 1.123.76
  2. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.37.7
  3. Upgrade

    Upgrade n8n to a version that resolves this vulnerability.

    Fixed in 2.38.2

Event History

Sep 8, 2026
CVE Published
via MITRE·09:24 PM
Data Sourced
via MITRE·09:24 PM
DescriptionWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An authenticated user with permission to edit workflows can exploit it by executing a workflow that uses the Git node clone operation with an attacker-controlled destination path.

2

Are default configurations affected?

Yes. The vulnerable regular expression is part of the default N8N_BLOCK_FILE_PATTERNS configuration.

3

What is the impact of successful exploitation?

The regular-expression match runs synchronously in the main n8n process and can freeze the n8n instance with a single workflow execution.

4

Which versions contain the fix?

The issue is fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203