PT-2026-94105 · N8N · N8N

·

CVE-2026-92588

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

5.9

Medium

VectorAV:N/AC:L/AT:P/PR:H/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.76 n8n versions prior to 2.37.7 n8n versions prior to 2.38.2
Description The source control push endpoint relies on file paths and status provided in the client request payload rather than server-side status computed for the user. This allows an authenticated project-scoped user to reference files from projects they are not authorized to access and push deletions of those workflows and credentials, leading to cross-project data destruction. This issue requires the Source Control (Environments) enterprise feature to be licensed, enabled, and connected to a remote repository.
Recommendations Update to version 1.123.76. Update to version 2.37.7. Update to version 2.38.2.

Exploit

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92588
GHSA-HVRX-JC5J-PG3W

Affected Products

N8N