GHSA-cqr2-h44g-v75v: n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
Summary
n8n had a security flaw where certain API endpoints didn't check if a user could access a specific project before showing that project's members' names and emails. An attacker with role-management permission could exploit this to view private information from any project on the system. The vulnerability has been patched in n8n versions 2.38.2 and 2.37.7.
Solution / Mitigation
Upgrade to n8n version 2.38.2 or 2.37.7 or later. If upgrading is not immediately possible, administrators can temporarily: (1) restrict n8n instance access to fully trusted users only, and (2) audit and revoke any custom global roles that carry the `role:manageProject` scope, limiting that scope to fully trusted users only. Note: these workarounds do not fully remediate the risk and are only short-term measures.
Vulnerability Details
EPSS: 0.3%
Yes
September 10, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-cqr2-h44g-v75v
First tracked: September 10, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 95%