Description
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.
Severity (CVSS)
| Base score | 6.3 |
|---|---|
| Severity | Medium |
| Version | CVSS 4.0 |
| Vector | CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N |
| Provided by | CNA |
Weaknesses
- CWE-287 — Improper Authentication
Affected products
| Vendor | Product | Versions |
|---|---|---|
| n8n | n8n | 0 to <1.123.22; 1.123.22; 2.0.0 to <2.9.3; 2.9.3; 2.10.0 to <2.10.1; 2.10.1 |
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-jh8h-6c9q-7gmw (vendor-advisory)
- https://www.vulncheck.com/advisories/n8n-authentication-bypass-in-chat-trigger-node (third-party-advisory)
Generated from the official CVE List on 16 Jul 2026 07:01 UTC.