Incorrect Authorization Affecting @n8n/client-oauth2 package, versions <1.11.2>=1.12.0 <1.12.1


Severity

Recommended
0.0
medium
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.27% (19th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-N8NCLIENTOAUTH2-18322332
  • published27 Jul 2026
  • disclosed22 Jul 2026
  • creditUnknown

Introduced: 22 Jul 2026

NewCVE-2026-65594  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade @n8n/client-oauth2 to version 1.11.2, 1.12.1 or higher.

Overview

Affected versions of this package are vulnerable to Incorrect Authorization in the OAuth 2.1 authorization. An attacker can gain unauthorized access to another user's workflow and execute it with the owner's credentials by registering an OAuth client and self-approving consent for a protected workflow. This allows the attacker to set inputs and read outputs, potentially exposing sensitive data from the owner's integrations.

Note: This is only exploitable if the instance has at least one active workflow using an MCP Server Trigger node configured with OAuth2 authentication.

Workaround

This vulnerability can be mitigated by restricting instance access to fully trusted users, auditing active workflows using the MCP Server Trigger with OAuth2 authentication, and considering switching to a different authentication method or deactivating affected workflows until a patch is applied.

References

CVSS Base Scores

version 4.0
version 3.1