Junglewise Threat Intelligence

CVE-2026-42228: n8n Hosted Chat WebSocket authorization bypass

CVE-2026-42228 · Severity: low · CVSS 3.1 · Published 2026-04-29

Technologies: N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation platform that includes a Hosted Chat feature allowing users to interact with workflows via a web-based chat interface. The Chat Trigger node's WebSocket endpoint failed to verify that incoming connections were authorized to access a specific workflow execution, allowing unauthenticated attackers to hijack waiting chat sessions, intercept user prompts, and inject arbitrary input to alter workflow behavior.

Technical details

The vulnerability is a missing authorization check (CWE-862) in the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature. The endpoint accepts connections identified by an execution ID but does not verify the caller is authorized to interact with that execution. An unauthenticated remote attacker who obtains a valid execution ID for a workflow in a waiting state can connect to the WebSocket, receive the pending prompt intended for the legitimate user, and submit arbitrary input to resume or manipulate downstream workflow logic. Exploitation requires three conditions: the workflow must be publicly exposed with authentication disabled (set to None), a target execution must be in a waiting state at the time of attack, and the attacker must discover or obtain the execution ID. Patches are available in n8n versions 1.123.32, 2.17.4, and 2.18.1.

Affected products

  • n8n n8n < 1.123.32, 2.0.0 to < 2.17.4, 2.18.0 to < 2.18.1

Timeline

  • 2026-04-29: disclosed
  • 2026-04-29: patched: Fixed in versions 1.123.32, 2.17.4, and 2.18.1

References

Related threats