Official source evidencegithub.comVersioned article
Official source article · github.com

Release n8n@1.123.76 · n8n-io/n8n · GitHub

BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.

Read the official article ↗
Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 08:30 UTC
Linked CVEs9

Linked CVE reports

These are source relationships, not a claim that this article fixes every affected product or branch.

  • CVE-2026-86082n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
  • CVE-2026-86993n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
  • CVE-2026-86994n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
  • CVE-2026-86076n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
  • CVE-2026-86079n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
  • CVE-2026-86084n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
  • CVE-2026-86995n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
  • CVE-2026-86083n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
  • CVE-2026-86080n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open

Source and provenance

Original title: Release n8n@1.123.76 · n8n-io/n8n · GitHub. Captured 27 Sept 2026, 08:30 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.

Open the publisher's current version ↗