CVE-2026-42226

high
Published 2026-05-04 · Modified 2026-05-08
CVSS v3
7.5
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:L
CVSS v2
VIR risk
7.5

Description

n8n's Credential Authorization Bypass in dynamic-node-parameters Allows Foreign API Key Replay

Predictions

Exploit likelihood
83%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: security-advisories@github.com — https://github.com/n8n-io/n8n/security/advisories/GHSA-r4v6-9fqc-w5jr

Package impact

EcosystemPackageVulnerableFixed
npm npmn8n>=2.17.0,<2.17.52.17.5
npm npmn8n<1.123.331.123.33
npm NPMn8n< 1.123.331.123.33
npm NPMn8n>= 2.17.0, < 2.17.52.17.5

Application impact

VendorProductVersionsFixed
n8nn8n{"endExcluding":"1.123.33"}1.123.33

References

CWEs

CWE-862

Verify integrity in audit chain (admin only). AS-IS.