Authorization bypass through user-controlled key in n8n - #VU127223

 

Authorization bypass through user-controlled key in n8n - #VU127223

Published: April 23, 2026


Vulnerability identifier: #VU127223
CSH Severity: Low
CVSS v4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: N/A
CWE-ID: CWE-639
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vendor: n8n
Affected software:
n8n

Detailed vulnerability description

The vulnerability allows a remote user to disclose sensitive information.

The vulnerability exists due to authorization bypass through a user-controlled key in the public API variables endpoint when handling requests with an arbitrary projectId query parameter. A remote user can supply a crafted projectId value to disclose sensitive information.

Only licensed enterprise or team deployments with multiple projects and the variables feature enabled are vulnerable.


Remediation

Install security update from vendor's website.

Sources