n8n Node.js Package < 1.123.76 / 2.0.x < 2.37.7 / 2.38.x < 2.38.2 Multiple Vulnerabilities

high Nessus Plugin ID 347980

Synopsis

The n8n Node.js Package installed on the remote host is affected by multiple vulnerabilities.

Description

The version of the n8n Node.js Package installed on the remote host is less than 1.123.76, or is 2.0.x prior to 2.37.7, or is 2.38.x prior to 2.38.2. It is, therefore, affected by multiple vulnerabilities:

- n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the legacy expression engine generated source text by calling the mutable global JSON.stringify while printing synthetic string literals and interpolating timezone data. An expression could replace JSON.stringify and cause later generated source to contain executable attacker-controlled code. The affected code-generation paths include packages/@n8n/expression-runtime/src/bridge/isolated-vm-bridge.ts and packages/@n8n/tournament/src/ExpressionBuilder.ts, and the issue does not affect the vm expression engine. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2.
(CVE-2026-86083)

- n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the OpenAI Chat Model node enforced credential allowed-domain restrictions for normal calls but not for the model-search dropdown. A workflow editor could set options.baseURL to an arbitrary host and make the searchModels path send the openAiApi credential there. The affected implementation is packages/@n8n/nodes-langchain/nodes/llms/LMChatOpenAi/methods/loadModels.ts, which omitted assertOpenAiCredentialAllowsUrl. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. (CVE-2026-86082)

- n8n is an open source workflow automation platform. Prior to 1.123.76, 2.37.7, and 2.38.2, the Git node clone operation matched an attacker-controlled destination path against the default N8N_BLOCK_FILE_PATTERNS regular expression. The pattern allowed catastrophic backtracking and ran synchronously in the main n8n process. An authenticated workflow editor could therefore freeze the instance with one workflow execution; the affected default is declared in packages/@n8n/config/src/configs/security.config.ts. This issue is fixed in versions 1.123.76, 2.37.7 and 2.38.2. (CVE-2026-86081)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number.

Solution

Upgrade to n8n Node.js Package version 1.123.76, 2.37.7, 2.38.2 or later.

See Also

https://github.com/n8n-io/n8n/security/advisories/GHSA-34ff-336r-5q23

https://github.com/n8n-io/n8n/security/advisories/GHSA-6xcw-7xm6-48c6

https://github.com/n8n-io/n8n/security/advisories/GHSA-j535-v25q-vx3q

Plugin Details

Severity: High

ID: 347980

File Name: n8n_nodejs_package_1_123_76.nasl

Version: 1.1

Type: Local

Agent: windows, macosx, unix

Family: Misc.

Published: 9/18/2026

Updated: 9/18/2026

Configuration: Enable thorough checks (optional)

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 58.22

CVSS v2

Risk Factor: High

Base Score: 9

Vector: CVSS2#AV:N/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-86083

CVSS v3

Risk Factor: High

Base Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS v4

Risk Factor: High

Base Score: 7.7

Vector: CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Vulnerability Information

CPE: cpe:/a:n8n:n8n

Required KB Items: Host/nodejs/modules/enumerated

Patch Publication Date: 9/2/2026

Vulnerability Publication Date: 9/8/2026

Reference Information

CVE: CVE-2026-86081, CVE-2026-86082, CVE-2026-86083

IAVB: 2026-B-0255