n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execu…
Medium CVSS 4.3
Summary
n8n versions before 2.36.2 contain a missing per-project authorization vulnerability in the Insights API routes that allows authenticated users with insights scopes to access workflow names and execution statistics across projects. Attackers can supply arbitrary projectId parameters to retrieve sensitive project and workflow information from projects they have no membership in.
In-depth triage
No in-depth report has been generated yet (DR-003 v2 AI pipeline is under construction).
Affected products
- :
Sources
- NVD DATABASE
Original Links
- https://github.com/n8n-io/n8n/security/advisories/GHSA-jmmj-93rg-6j39 Mitigation
- https://www.vulncheck.com/advisories/n8n-before-2.36.2-missing-authorization-via-insights-api Third Party Advisory
Timeline
- nvd_ingest NVD