Open redirect in n8n - CVE-2026-42230

 

Open redirect in n8n - CVE-2026-42230

Published: April 23, 2026


Vulnerability identifier: #VU127226
CSH Severity: Medium
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-42230
CWE-ID: CWE-601
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to redirect users to an external site and disclose limited sensitive information.

The vulnerability exists due to improper input validation in the MCP OAuth consent flow when handling OAuth client registration and consent denial requests. A remote attacker can register an arbitrary redirect_uri and send a crafted phishing link to redirect users to an attacker-controlled site and disclose limited sensitive information.

User interaction is required, and exploitation occurs if the victim clicks "Deny" on the consent page.


Affected software

n8n

How to mitigate CVE-2026-42230

Install security update from vendor's website.

n8n - addressed in versions 1.123.32, 2.17.4, 2.18.1

External References

Related Security Bulletins