Impact
The vulnerability in n8n allows an unauthenticated user to reuse a previously obtained resumeToken on the /chat WebSocket endpoint. Because the server does not verify that the target node supports chat messages, an attacker can bypass approval gates such as Send‑and‑Wait, non‑chat HITL, or Wait approval gates. This results in an unauthorized release of a paused workflow, effectively granting the attacker the ability to trigger parts of a workflow without proper authorization. The weakness is an authorization bypass, recorded as CWE‑862.
Affected Systems
Products from n8n‑io, specifically the n8n workflow automation platform. Versions prior to 2.37.7 and 2.38.2 are affected. The issue is fixed in 2.37.7 and 2.38.2.
Risk and Exploitability
The CVSS score of 6.3 places the vulnerability in the moderate range. The EPSS score is not available, indicating no published exploitation data. The vulnerability is not listed in the CISA KEV catalog. The attack vector is web‑based via the WebSocket API; an attacker only needs to possess a valid resumeToken, which could be obtained through other anonymous form submissions. Because the vulnerable code bypasses authorization checks, the exploit requires only a browser or WebSocket client and does not need privileged credentials.
OpenCVE Enrichment
Github GHSA