Description
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow accessible to the consenting user. This issue is fixed in versions 2.37.7 and 2.38.1.
Published: 2026-09-08
Score: 5.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Unauthorized token acquisition enabling access to unapproved workflows
Action: Immediate Patch
AI Analysis

Impact

The flaw lies in OAuth token handling: a refresh token can be reused to request an access token for any registered resource, regardless of the original grant. As a consequence, an OAuth client that was approved for one workflow can substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow that the consenting user can access. This results in unauthorized use of the user's account to run or read data from a workflow the user did not approve, effectively bypassing the intended consent boundaries and raising the risk of data exposure or unintended automation.

Affected Systems

n8n, the open‑source workflow automation platform, is affected in all releases older than 2.37.7 and 2.38.1. Versions 2.37.7 and 2.38.1 introduce the fix that binds refresh tokens to the original resource grant.

Risk and Exploitability

The CVSS score of 5.9 indicates moderate severity, and the vulnerability is not listed in CISA’s KEV catalog. The EPSS score of 0.0032 (less than 1%) indicates a very low but nonzero probability of exploitation. The issue can be exploited by any party possessing an existing OAuth refresh token or by an attacker who can trick a user into authorizing a malicious client that then performs a token refresh using a substituted resource. The attack vector is a web‑application OAuth interaction and does not require elevated privileges or direct access to the n8n codebase.

Generated by OpenCVE AI on September 10, 2026 at 03:42 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade n8n to version 2.37.7 or later (or 2.38.1) to implement the binding of refresh tokens to the original resource grant.
  • After upgrading, disable or remove any OAuth clients that received tokens before the patch.
  • Re‑authorize all workflows that rely on OAuth authentication and verify OAuth client configurations enforce strict resource binding to mitigate the CWE-863 flaw.

Generated by OpenCVE AI on September 10, 2026 at 03:42 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cw9w-vv67-hf73 n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
History

Fri, 11 Sep 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
cpe:2.3:a:n8n:n8n:2.38.0:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L'}


Wed, 09 Sep 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 08 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.1, the OAuth token endpoint bound an authorization code's first access token to the consented resource but did not bind its refresh token. Refreshing checked only that the requested resource was registered, not that it matched the original grant. An OAuth client approved for one workflow could substitute a different workflow URL in the resource parameter and obtain a valid token for an unapproved workflow accessible to the consenting user. This issue is fixed in versions 2.37.7 and 2.38.1.
Title n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution
Weaknesses CWE-863
References
Metrics cvssV4_0

{'score': 5.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-09T15:58:40.814Z

Reserved: 2026-09-04T19:34:03.100Z

Link: CVE-2026-86073

cve-icon Vulnrichment

Updated: 2026-09-09T15:58:37.999Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T17:18:39.167

Modified: 2026-09-11T18:07:39.963

Link: CVE-2026-86073

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-27T18:15:12Z

Weaknesses