CVE Explorer
CVE-2026-65594
n8n before 2.29.8 and 2.30.x before 2.30.1 (affected from 2.27.0, when the OAuth 2.1 consent and token-issuance flow was introduced) does not verify that the authenticated user has access to the workflow referenced as the OAuth resource. On instances with at least one active MCP Server Trigger workflow configured with n8n OAuth2 authentication, a member-level user can register an OAuth client, self-approve consent for another user's workflow, and obtain a valid token. The workflow then runs in t
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 2 assertions
{"defaultStatus":"unaffected","packageURL":"pkg:npm/n8n","product":"n8n","vendor":"n8n-io","versions":[{"lessThan":"2.30.1","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"2.30.1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/affected/0
{"defaultStatus":"unaffected","packageURL":"pkg:npm/n8n","product":"n8n","vendor":"n8n-io","versions":[{"lessThan":"2.29.8","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"2.29.8","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/affected/1
Affected products and versions
2 source assertions{"defaultStatus":"unaffected","packageURL":"pkg:npm/n8n","product":"n8n","vendor":"n8n-io","versions":[{"lessThan":"2.30.1","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"2.30.1","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/affected/0
{"defaultStatus":"unaffected","packageURL":"pkg:npm/n8n","product":"n8n","vendor":"n8n-io","versions":[{"lessThan":"2.29.8","status":"affected","version":"0","versionType":"semver"},{"status":"unaffected","version":"2.29.8","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackRequirements":"PRESENT","attackVector":"NETWORK","baseScore":5.1,"baseSeverity":"MEDIUM","privilegesRequired":"LOW","subAvailabilityImpact":"NONE","subConfidentialityImpact":"HIGH","subIntegrityImpact":"LOW","userInteraction":"NONE","vectorString":"CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:L/SA:N","version":"4.0","vulnAvailabilityImpact":"NONE","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"},"metric_type":"cvssV4_0"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/problemTypes/0/descriptions/0
Source references
2 source assertions{"name":"GitHub Security Advisory (GHSA-q5xf-xhwf-cwqf)","tags":["vendor-advisory"],"url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-q5xf-xhwf-cwqf"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/references/0
{"name":"VulnCheck Advisory: n8n before 2.30.1 Missing OAuth Authorization Check","tags":["third-party-advisory"],"url":"https://www.vulncheck.com/advisories/n8n-before-missing-oauth-authorization-check"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:9e5657abec591f0a71d7502b19d4e7b1a253f40238d1b8db87181abda57cc3b0 · sha256:b3ba5bf9c57cfbf6… · /containers/cna/references/1
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.