Description
n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email addresses. The affected controller is packages/cli/src/controllers/role.controller.ts, which omitted the project:list scope check. This issue is fixed in versions 2.37.7 and 2.38.2.
Published: 2026-09-08
Score: 5.1 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Information Disclosure
Action: Patch
AI Analysis

Impact

An attacker with a role that includes role:manageProject can request member information for any project by using the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints. Because the controller omitted the project:list permission check, the API returns the names and email addresses of members belonging to a project the caller could not list. The vulnerability is a classic example of missing authorization (CWE‑862) and results in the confidential personal information of users being disclosed to an unauthorized user. The impact is the exposure of PII across tenant boundaries, compromising confidentiality but not providing control or data modification capabilities.

Affected Systems

The problem exists in the n8n workflow automation platform. Versions prior to 2.37.7 and prior to 2.38.2 contain the vulnerability, as the role controller in packages/cli/src/controllers/role.controller.ts omitted the necessary project scope check. The fix was included in releases 2.37.7 and 2.38.2, so any installation running those or newer releases is no longer vulnerable.

Risk and Exploitability

The CVSS score of 5.1 indicates a low‑to‑medium severity vulnerability. No EPSS score is available, and the issue is not listed in the CISA KEV catalog. An authenticated user with the manageProject privilege can exploit the flaw by calling the exposed API endpoints and providing arbitrary project identifiers. Because the attacker only needs existing role:manageProject permissions, lateral movement within a tenant is not required; the weakness is purely an authorization oversight. The risk is primarily the unauthorized PII disclosure and should be addressed promptly by applying the patch.

Generated by OpenCVE AI on September 9, 2026 at 08:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to n8n version 2.37.7 or later, including 2.38.2, to apply the patch that restores the missing project scope check.
  • Review and restrict the use of role:manageProject so that only trusted administrators are granted it; additionally enforce the project:list scope or equivalent per‑project permission checks when assigning roles.
  • Enable comprehensive logging of assignment endpoint activity and regularly audit calls to /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members to detect any unauthorized cross‑tenant usage.

Generated by OpenCVE AI on September 9, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-cqr2-h44g-v75v n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
History

Mon, 14 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 21:15:00 +0000

Type Values Removed Values Added
First Time appeared N8n
N8n n8n
CPEs cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:*
Vendors & Products N8n
N8n n8n
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Tue, 08 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Description n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /rest/roles/:slug/assignments and /rest/roles/:slug/assignments/:projectId/members endpoints checked only whether the caller could manage the role type. A caller with role:manageProject could name a project the caller could not list and obtain member names and email addresses. The affected controller is packages/cli/src/controllers/role.controller.ts, which omitted the project:list scope check. This issue is fixed in versions 2.37.7 and 2.38.2.
Title n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 5.1, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-14T12:02:18.643Z

Reserved: 2026-09-04T19:34:03.101Z

Link: CVE-2026-86085

cve-icon Vulnrichment

Updated: 2026-09-14T12:02:14.533Z

cve-icon NVD

Status : Analyzed

Published: 2026-09-08T22:19:17.670

Modified: 2026-09-14T13:18:57.623

Link: CVE-2026-86085

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:06:12Z

Weaknesses