BlackTreeCVE IntelligenceOfficial source evidencegithub.comVersioned article
Official source article · github.com
Release n8n@2.38.2 · n8n-io/n8n · GitHub
BlackTree keeps a versioned source snapshot and links it to relevant CVE reports. The publisher remains authoritative for product applicability, release details and installation guidance.
Read the official article ↗Publishergithub.com
Article IDNo stable ID in source URL
Verified snapshot27 Sept 2026, 08:30 UTC
Linked CVEs15
Linked CVE reports
These are source relationships, not a claim that this article fixes every affected product or branch.
- CVE-2026-86077n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket
- CVE-2026-86082n8n: Domain-Restriction Bypass via Unguarded Model-Search Endpoint in OpenAI Chat Model Node
- CVE-2026-86085n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
- CVE-2026-86074n8n: Instance AI Credential Setup Accepts Unvalidated Probe URL from Fetched Content
- CVE-2026-86993n8n: Log Streaming Event Destinations Decrypt Generic-Auth Credentials Without Ownership Check
- CVE-2026-86078n8n: Prototype Pollution via Workflow Structure Summary Can Lead to Denial of Service
- CVE-2026-86075n8n: Unauthenticated Persistent Storage Exhaustion via OAuth Dynamic Client Registration Endpoint
- CVE-2026-86994n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter
- CVE-2026-86076n8n: Expression Sandbox Escape in Editor-UI Enables Stored Cross-User JavaScript Execution
- CVE-2026-86079n8n: Path Injection in Elasticsearch and ElasticSecurity Nodes via Unencoded Identifiers
- CVE-2026-86996n8n: Agent Workflow Tool Bypasses Sub-Workflow Caller Policy
- CVE-2026-86084n8n: Disabled OIDC SSO Endpoints Remain Active and Issue Valid Sessions
- CVE-2026-86995n8n: Git Node branch.<name>.remote Config Key Bypasses Sandbox Path Restriction, Enabling Local Git Repository Read
- CVE-2026-86083n8n: Expression Sandbox Escape via Shared Builtin Tampering and Code-Printer Injection Leads to Code Execution
- CVE-2026-86080n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
Source and provenance
Original title: Release n8n@2.38.2 · n8n-io/n8n · GitHub. Captured 27 Sept 2026, 08:30 UTC. The stored article is used for enrichment and change detection; BlackTree does not republish the publisher's full text here.
Open the publisher's current version ↗