Incorrect Authorization Affecting @n8n/n8n-nodes-langchain package, versions <1.122.46>=2.0.0-rc.0 <2.31.3>=2.32.0 <2.32.1


Severity

Recommended
0.0
high
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.22% (13th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications

Snyk Learn

Learn about Incorrect Authorization vulnerabilities in an interactive lesson.

Start learning
  • Snyk IDSNYK-JS-N8NN8NNODESLANGCHAIN-18323530
  • published27 Jul 2026
  • disclosed22 Jul 2026
  • creditnlg.bao1340

Introduced: 22 Jul 2026

CVE-2026-72763  (opens in a new tab)
CWE-863  (opens in a new tab)

How to fix?

Upgrade @n8n/n8n-nodes-langchain to version 1.122.46, 2.31.3, 2.32.1 or higher.

Overview

@n8n/n8n-nodes-langchain is a Banner image

Affected versions of this package are vulnerable to Incorrect Authorization via the Execute Sub-workflow. An attacker can access unauthorized credentials by referencing credential IDs within inline workflow JSON, bypassing intended access controls.

Note: This is only exploitable if workflow sharing is enabled and the attacker has been explicitly granted Editor access to a shared workflow, and knows the target credential's ID.

Workaround

This vulnerability can be mitigated by restricting workflow sharing to fully trusted users, avoiding granting Editor access to untrusted members on workflows that use sensitive credentials, auditing shared workflows for Execute Sub-workflow nodes with Source = "Parameter" and reviewing their inline workflow definitions for unexpected credential references, and restricting network egress from the instance to prevent connections to attacker-controlled endpoints.

CVSS Base Scores

version 4.0
version 3.1