Executive brief
n8n is a workflow automation platform that allows users to create and manage workflows across projects. An authenticated user with permission to create workflows could exploit an authorization flaw to assign their workflows to folders in other projects they don't have access to, disrupting the logical structure of those projects. While the workflow itself remains hidden and no project data is exposed, this vulnerability creates unauthorized database-level modifications to folder structures in target projects.
Technical details
This improper authorization vulnerability (CWE-639) allows authenticated users to bypass project and folder authorization boundaries during workflow creation by submitting crafted request payloads. The vulnerability requires the attacker to have existing permissions to create workflows in at least one project, and affects only instances with multi-project and folder support enabled. An attacker cannot view or access data in the target project; the impact is limited to logical integrity violations where workflows are associated with folders outside the attacker's authorized project scope. The issue is fixed in n8n version 2.28.0 and later.
Affected products
- n8n n8n < 2.28.0
Timeline
- 2026-06-24: disclosed: Advisory GHSA-2xgm-wc4g-5jvg published
- 2026-06-24: patched: Fix available in version 2.28.0
- 2026-07-08: other: Duplicate advisory GHSA-gqcv-rfj6-r29g published
- 2026-07-22: other: Duplicate advisory GHSA-gqcv-rfj6-r29g withdrawn