Authorization bypass through user-controlled key in n8n - #VU127223
Published: April 23, 2026
n8n
Detailed vulnerability description
The vulnerability allows a remote user to disclose sensitive information.
The vulnerability exists due to authorization bypass through a user-controlled key in the public API variables endpoint when handling requests with an arbitrary projectId query parameter. A remote user can supply a crafted projectId value to disclose sensitive information.
Only licensed enterprise or team deployments with multiple projects and the variables feature enabled are vulnerable.