Improper access control in n8n - CVE-2026-42228
Published: April 23, 2026
Vulnerability details
The vulnerability allows a remote attacker to disclose sensitive information and influence downstream workflow behavior.
The vulnerability exists due to improper access control in the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature when handling connections to a target execution. A remote attacker can connect to a waiting execution using a valid execution ID to disclose sensitive information and influence downstream workflow behavior.
Exploitation requires a public Hosted Chat workflow with authentication set to none, a target execution in a waiting state, and knowledge of the execution ID for that waiting execution.