GHSA-5vfw-jc4p-fj39Medium▾ SunlitDuplicate Advisory: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
▾ Sunlit zone — Low / medium · no exploitation signal
impact 27.5 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
This advisory has been withdrawn because it is a duplicate of GHSA-q5xf-xhwf-cwqf. This link is maintained to preserve external references.
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in the owner's project context with the owner's stored credentials, and the attacker can set tool inputs and read outputs (potentially including data from the owner's connected integrations), breaking user and project isolation.
n8n < 2.29.8Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2026-65594Mediumn8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
CVE-2026-86073High· 7.6n8n is an open source workflow automation platform
GHSA-88c4-pcqm-3r9pMediumDuplicate Advisory: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction
GHSA-6qc9-mqvw-jg7xHighn8n: Credential Authorization Bypass via Expression in HTTP Request Node `genericAuthType`
GHSA-cj9h-qx8g-pq2gHighn8n: Shared-Workflow Editor Can Exfiltrate Credentials via Inline Sub-Workflow JSON
CVE-2026-65596Mediumn8n: GraphQL Node Bypasses "Allowed HTTP Request Domains" Restriction