Junglewise Threat Intelligence

n8n account takeover in Token Exchange Embed Login

Severity: high · CVSS 8.9 · Published 2026-07-22

Technologies: N8n-Io N8n. Vendors: N8n.

Executive brief

n8n is a workflow automation tool used to connect various business applications. A security flaw in its 'embed login' feature allows an attacker to take over any user account, including administrator accounts, by providing a specially crafted login token. This could lead to full control over the automation platform, exposure of sensitive credentials, and disruption of business operations.

Technical details

An authentication bypass vulnerability exists in n8n's Token Exchange Embed Login feature due to insufficient verification of data authenticity (CWE-345) and incorrect authorization (CWE-863). When processing a validly-signed incoming token, the service fails to verify if the email claim is verified by the issuer and does not check if the trusted key's permitted role ceiling covers the target account. An attacker with the ability to obtain a token from a trusted issuer (e.g., one that emits unverified email addresses) can impersonate any existing user. This vulnerability requires the 'embed login' feature to be enabled and at least one trusted key source to be configured. The issue is patched in versions 2.31.5 and 2.32.1.

Affected products

  • n8n-io n8n < 2.31.5, >= 2.32.0 < 2.32.1

Timeline

  • 2026-07-22: advisory: GitHub Advisory GHSA-8342-988q-86cr published
  • 2026-07-22: patched: Fixes released in versions 2.31.5 and 2.32.1

References

Related threats