Executive brief
n8n, a popular workflow automation tool, contains a security flaw in how it handles shared credentials for external services like Google or Slack. An authorized user with limited 'read-only' access to a shared credential can overwrite it with their own account details. This allows the attacker to hijack automated workflows, potentially leading to data theft or unauthorized access to corporate integrations.
Technical details
A cross-user authorization bypass exists in n8n's OAuth1 and OAuth2 credential reconnect endpoints. The root cause is an incorrect permission check where the system validates 'credential:read' instead of 'credential:update' before allowing a token refresh/reconnect flow. An authenticated attacker with read access to a shared credential can initiate a reconnect flow to bind the credential to an external OAuth account they control. Consequently, any workflows using that shared credential will execute using the attacker's identity, facilitating data exfiltration. The issue is fixed in versions 1.123.43, 2.20.7, and 2.21.1.
Affected products
- n8n-io n8n < 1.123.43, >= 2.0.0-rc.0, < 2.20.7, >= 2.21.0, < 2.21.1
Timeline
- 2026-05-13: disclosed
- 2026-05-14: advisory