Improper Authorization in n8n - #VU146790
Published: September 2, 2026
Vulnerability details
The vulnerability allows a remote user to delete workflows and credentials across projects.
The vulnerability exists due to improper authorization in the source control push endpoint when processing a push request with file paths and status from the request payload. A remote privileged user can submit a crafted push request naming files from other projects to delete workflows and credentials across projects.
The issue is exploitable only when the Source Control (Environments) enterprise feature is licensed, enabled, and connected to a remote repository.