{"data":{"id":"1fe2892d-c271-4fd2-9047-9fe91e9a963c","title":"GHSA-65xw-2v52-jhxc: n8n: Cross-User Active Workflow ID and Lifecycle Event Disclosure via Missing userId Filter","summary":"n8n, a workflow automation tool, had a security flaw where the `/rest/active-workflows` endpoint (an API endpoint that returns information) showed all active workflow IDs to any user on the instance, regardless of permissions. Additionally, events about workflow activation, deactivation, and publishing were broadcast to all connected clients with sensitive details like workflow IDs and error information, leaking data across different users.","solution":"The issue has been fixed in n8n versions 1.123.76, 2.37.7, and 2.38.2. Users should upgrade to one of these versions or later to remediate the vulnerability. If upgrading is not immediately possible, administrators should restrict n8n instance access to fully trusted users only and avoid provisioning 'global:member' accounts for untrusted users until the instance is patched, though these workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-65xw-2v52-jhxc","publishedAt":"2026-09-10T21:01:27.000Z","cveId":"CVE-2026-86994","cweIds":null,"cvssScore":null,"cvssSeverity":"medium","severity":"medium","attackType":["pii_leakage"],"issueType":"vulnerability","affectedPackages":["n8n@>= 2.0.0, < 2.37.7 (fixed: 2.37.7)","n8n@>= 2.38.0, < 2.38.2 (fixed: 2.38.2)","n8n@< 1.123.76 (fixed: 1.123.76)"],"affectedVendors":["LangChain"],"affectedVendorsRaw":["n8n"],"classifierModel":"claude-haiku-4-5-20251001","classifierPromptVersion":"v3","cvssVector":null,"attackVector":null,"attackComplexity":null,"privilegesRequired":null,"userInteraction":null,"exploitMaturity":"unknown","epssScore":0.00246,"patchAvailable":true,"disclosureDate":"2026-09-10T21:01:27.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"api","llmSpecific":false,"classifierConfidence":0.75,"researchCategory":null,"atlasIds":null}}