GHSA-8342-988q-86cr: n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login
In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check that the trusted key’s permitted role ceiling covered that account, nor that the email claim was verified. As a result, anyone able to obtain a token accepted by one of the configured trusted keys, for example a trusted issuer that emitted unverified email addresses, could authenticate as any existing user, gaining full account control.
This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.
References
Code Behaviors & Features
Detect and mitigate GHSA-8342-988q-86cr with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →