Incorrect Authorization Affecting n8n package, versions <2.29.8>=2.30.0 <2.30.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.47% (39th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-N8N-18322065
  • published27 Jul 2026
  • disclosed22 Jul 2026
  • creditodgrso

Introduced: 22 Jul 2026

NewCVE-2026-65595  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade n8n to version 2.29.8, 2.30.1 or higher.

Overview

n8n is a n8n Workflow Automation Tool

Affected versions of this package are vulnerable to Incorrect Authorization in the Token Exchange process. An attacker can gain elevated privileges and execute arbitrary code by obtaining a valid external JWT accepted by a configured trusted key, which allows invoking administrator-only Public API operations such as role escalation, user creation, and user deletion.

Note: This is only exploitable if both the Token Exchange feature and the Public API are enabled, and the attacker can obtain an external JWT trusted by a configured issuer. Role escalation additionally requires an Advanced Permissions license; Community Package installation additionally requires both N8N_COMMUNITY_PACKAGES_ENABLED=true and N8N_UNVERIFIED_PACKAGES_ENABLED=true.

Workaround

This vulnerability can be mitigated by disabling the Token Exchange feature by setting N8N_TOKEN_EXCHANGE_ENABLED=false or N8N_ENV_FEAT_TOKEN_EXCHANGE=false, restricting Public API access at the network level to trusted clients only, or disabling unverified Community Package installation by setting N8N_UNVERIFIED_PACKAGES_ENABLED=false.

References

CVSS Base Scores

version 4.0
version 3.1