GHSA-q5xf-xhwf-cwqf: n8n: Member-Level Users Can Execute Other Users' MCP Server Trigger Workflows via Missing OAuth Authorization Check
Summary
n8n versions 2.27.0 and later have a security flaw where member-level users can bypass OAuth authorization checks (a security protocol that verifies user permissions) to run workflows belonging to other users. An attacker can register an OAuth client (an application that requests permission to access resources), approve access to another user's workflow, and obtain a token (a credential proving authorization) that lets them execute that workflow, potentially accessing the owner's data while the execution appears under the owner's account.
Solution / Mitigation
The issue has been fixed in n8n versions 2.29.8 and 2.30.1. Users should upgrade to one of these versions or later. If upgrading is not immediately possible, administrators can temporarily restrict n8n instance access to fully trusted users only, or audit and deactivate workflows using MCP Server Trigger nodes with n8n OAuth2 authentication until the patch is applied.
Vulnerability Details
EPSS: 0.0%
Yes
July 22, 2026
Classification
Affected Vendors
Affected Packages
Original source: https://github.com/advisories/GHSA-q5xf-xhwf-cwqf
First tracked: July 22, 2026 at 08:01 PM
Classified by LLM (prompt v3) · confidence: 75%