Advisory Database
  • Advisories
  • Dependency Scanning
  1. npm
  2. ›
  3. n8n
  4. ›
  5. GHSA-8342-988q-86cr

GHSA-8342-988q-86cr: n8n: Account Takeover via Unverified Email Claim in Token Exchange Embed Login

July 22, 2026

In an n8n instance, when a validly-signed incoming token was matched to a local account by its email claim, the service did not check that the trusted key’s permitted role ceiling covered that account, nor that the email claim was verified. As a result, anyone able to obtain a token accepted by one of the configured trusted keys, for example a trusted issuer that emitted unverified email addresses, could authenticate as any existing user, gaining full account control.

This issue only affects instances where the embed login feature is enabled and at least one trusted key source is configured.

References

  • github.com/advisories/GHSA-8342-988q-86cr
  • github.com/n8n-io/n8n/commit/f69dfc6dd2178a14ea1624d2e1d403c2e755042f
  • github.com/n8n-io/n8n/releases/tag/n8n@2.31.5
  • github.com/n8n-io/n8n/releases/tag/n8n@2.32.1
  • github.com/n8n-io/n8n/security/advisories/GHSA-8342-988q-86cr

Code Behaviors & Features

Detect and mitigate GHSA-8342-988q-86cr with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions before 2.31.5, all versions starting from 2.32.0 before 2.32.1

Fixed versions

  • 2.31.5
  • 2.32.1

Solution

Upgrade to versions 2.31.5, 2.32.1 or above.

Impact 9.9 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-345: Insufficient Verification of Data Authenticity
  • CWE-863: Incorrect Authorization

Source file

npm/n8n/GHSA-8342-988q-86cr.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:16:44 +0000.