n8n is vulnerable to Insufficient Verification of Data Authenticity
89
High Risk
Token Exchange Embed Login matches a validly signed incoming token to a local account by email claim without verifying that the email claim is verified or that the trusted key's permitted role ceiling covers that account. Anyone who can obtain a token accepted by a configured trusted key can authenticate as any existing user and take over the account. The fix requires a verified email claim and enforces the trusted key's role ceiling before completing the exchange.
You are affected if you are using a version that falls within the vulnerable range and have the embed login feature enabled with at least one trusted key source configured.
n8n is vulnerable to Insufficient Verification of Data Authenticity in versions 2.17.0 - 2.31.4 and 2.32.0 - 2.32.0.
Upgrade the n8n library to the patch version.
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant