Executive brief
n8n is a workflow automation tool used to connect various business applications and automate tasks. A security flaw allows users who should only be able to view workflows to actually run them. This could lead to unauthorized data changes, unintended emails or messages being sent, and other side effects in connected business systems.
Technical details
An authorization bypass exists in the POST /workflows/{workflowId}/test-runs/new endpoint of n8n. The application incorrectly validates the 'workflow:read' scope instead of the required 'workflow:execute' scope when a user attempts to trigger a new evaluation test run. An authenticated attacker with low privileges (read-only access) can exploit this to trigger a real execution of a workflow via the internal runner. This can result in unintended outbound API calls and data mutations in any downstream systems connected to the workflow. The vulnerability is fixed in versions 1.123.55, 2.25.7, and 2.26.2.
Affected products
- n8n n8n < 1.123.55, < 2.25.7, < 2.26.2
Timeline
- 2026-06-10: advisory: GitHub Security Advisory published
- 2026-07-08: disclosed: NVD publication date