Impact
This vulnerability arises from a path‑traversal flaw in the generation of signed resume URLs used by Send‑and‑Wait approval gates in n8n. Because node identifiers can be supplied by a workflow creator, the signed URL can reference folders outside the intended project, enabling an attacker with workflow creation rights to craft a URL that targets an approval step in a project that the attacker otherwise cannot access. This bypasses normal access controls and leads to unauthorized approval of workflow steps, constituting a form of privilege escalation or workflow forgery.
Affected Systems
The issue affects n8n and all releases before 1.123.80, 2.39.6, and 2.40.1, as issued by n8n‑io. The vulnerability is tied to the CVE-2026-103254 ID and is documented by n8n’s advisory. Versions from 1.123.80 onward, 2.39.6 onward, and 2.40.1 onward include the fixed signed URL handling logic and are not impacted.
Risk and Exploitability
With a CVSS score of 7 the flaw is classified as high severity, yet its Exploit Prediction Scoring System (EPSS) score is not published, and it is not currently listed in the CISA KEV catalog. The exploit requires an attacker to possess workflow‑creation permissions and to manipulate node identifiers, prerequisites that limit the attack surface. Nonetheless, for organizations that delegate workflow creation to users who are not fully trusted, the vulnerability presents a medium‑to‑high risk of cross‑project approval forgery and related workflow execution misconduct.
OpenCVE Enrichment