Executive brief
n8n is a workflow automation platform that connects different applications and services. An attacker can inject malicious code through the OAuth client registration feature that executes in a victim's browser when they interact with revoked access notifications, potentially allowing theft of login credentials, session tokens, or unauthorized modification of workflows.
Technical details
The vulnerability exists in n8n's Model Context Protocol (MCP) OAuth client implementation, specifically in how the client_name parameter is handled in toast notifications. An unauthenticated attacker can register a malicious MCP OAuth client with injected JavaScript code in the client_name field. When a victim authorizes the OAuth consent dialog and a second user revokes that access, a toast notification renders the client_name without proper output encoding, allowing the injected script to execute in the victim's authenticated browser session. This enables attackers to steal session tokens, credentials, manipulate workflows, or escalate privileges. The vulnerability affects n8n versions before 1.123.32, 2.17.4, and 2.18.1, with patches available in those versions or later.
Affected products
- n8n n8n < 1.123.32, 2.17.0-2.17.3, 2.18.0
Timeline
- 2026-04-29: disclosed: Advisory published
- 2026-04-22: patched: Fix available in versions 1.123.32, 2.17.4, and 2.18.1