n8n Multiple Vulnerabilities in Workflow Execution and Access Control
Five security vulnerabilities were disclosed in n8n affecting regular expression denial of service, domain-restriction bypass, approval-gate bypass, workflow disclosure, and prototype pollution. The vulnerabilities could allow authenticated users to freeze instances, bypass domain restrictions, bypass approval gates, disclose workflow information, or cause denial of service.
Disclosed 10 September 2026 · Record updated 13 September 2026
Impact
Multiple vulnerabilities affecting instance stability, access control, and information disclosure. An authenticated user could freeze an instance with a crafted Git path; domain restrictions on credentials could be bypassed; anonymous users could bypass approval gates; workflow IDs could be disclosed across users; and prototype pollution could cause denial of service.
Our coverage
No articles linked to this incident yet.
Sources
- github.comhttps://github.com/advisories/GHSA-j535-v25q-vx3q
- github.comhttps://github.com/advisories/GHSA-34ff-336r-5q23
- github.comhttps://github.com/advisories/GHSA-35jj-42hp-8gmq
- github.comhttps://github.com/advisories/GHSA-65xw-2v52-jhxc
- github.comhttps://github.com/advisories/GHSA-679f-58pq-4v2c
