CVE-2026-86995
Last modified
CVE-2026-86995 is a medium-severity vulnerability rated 4.3/10 on the CVSS scale. n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. EPSS estimates a 0.32% chance of exploitation in the next 30 days.
Description
n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node validated the repository parameter for fetch or pull, but setUpstream wrote a branch..remote value into repository configuration without validating it. A later fetch or pull resolved the remote from that configuration instead of the checked parameter. An authenticated workflow editor could therefore point Git at any local repository readable by the n8n process and receive its contents through packages/nodes-base/nodes/Git/GenericFunctions.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| N8n | N8n | < 1.123.76 |
| N8n | N8n | >= 2.0.0, < 2.37.7 |
| N8n | N8n | >= 2.38.0, < 2.38.2 |
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-qgpw-8g46-w95vMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-86995?
How severe is CVE-2026-86995?
How do I fix CVE-2026-86995?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-8696radare2 6.1.5 contains a use-after-free vulnerability in the…9.8
- CVE-2026-8697Due to improper enforcement of authentication rate-limiting …8.8
- CVE-2026-8698The Cryptocurrency Prijsvergelijking Widget plugin for WordP…6.4
- CVE-2026-8699A stored Cross-Site Scripting (XSS) vulnerability has been i…7
- CVE-2026-86993n8n is an open source workflow automation platform. Prior to…4.9
- CVE-2026-86994n8n is an open source workflow automation platform. Prior to…4.3
- CVE-2026-86996n8n is an open source workflow automation platform. Prior to…5.4
- CVE-2026-8700Crypt::DSA versions before 1.20 for Perl generate seeds usin…7.3
- CVE-2026-8701The GNTT Post Title Ticker plugin for WordPress is vulnerabl…6.4
- CVE-2026-87011Open WebUI is an extensible, feature-rich, and user-friendly…7.5
- CVE-2026-87012Open WebUI is an extensible, feature-rich, and user-friendly…4.3
- CVE-2026-87013Open WebUI is an extensible, feature-rich, and user-friendly…4.3
Are you affected by CVE-2026-86995?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
