Impact
A flaw in the Send and Wait node allows an attacker to submit resume requests in Approve Within Chat mode without properly verifying the requester’s identity or approval rights. This bypass lets an unauthenticated user advance waiting executions and trigger actions that are normally protected by approval gates, compromising the integrity of workflow automation. The weakness is a direct failure of authorization checks.
Affected Systems
The vulnerability exists in n8n-io’s n8n product for all releases prior to versions 2.39.6 and 2.40.0 before 2.40.1. Users running these affected builds are at risk.
Risk and Exploitability
The CVSS score of 6.3 indicates moderate severity. No EPSS data is available, and the vulnerability is not listed in CISA’s KEV catalog. Because the flaw resides in a node that can be configured within a workflow, the likely attack path involves an attacker gaining access to the node’s configuration or interacting with the chat mode, which may require local or internal access. The lack of direct publicly disclosed exploitation evidence reduces immediate risk, though the permission skip is severe enough to warrant mitigation.
OpenCVE Enrichment