Impact
The flaw lies in OAuth token handling: a refresh token can be reused to request an access token for any registered resource, regardless of the original grant. As a consequence, an OAuth client that was approved for one workflow can substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow that the consenting user can access. This results in unauthorized use of the user's account to run or read data from a workflow the user did not approve, effectively bypassing the intended consent boundaries and raising the risk of data exposure or unintended automation.
Affected Systems
n8n, the open‑source workflow automation platform, is affected in all releases older than 2.37.7 and 2.38.1. Versions 2.37.7 and 2.38.1 introduce the fix that binds refresh tokens to the original resource grant.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score of 0.0032 (less than 1%) indicates a very low but nonzero probability of exploitation. The issue can be exploited by any party possessing an existing OAuth refresh token or by an attacker who can trick a user into authorizing a malicious client that then performs a token refresh using a substituted resource. The attack vector is a web‑application OAuth interaction and does not require elevated privileges or direct access to the n8n codebase.
OpenCVE Enrichment
Github GHSA