VDB

GCVE-110-NCSC-2026-228

GCVE-110-NCSC-2026-228
Advisory PublishedCVSS 5.0/10
Vulnetix · Advisory published July 13, 2026
n8n versions prior to 2.28.0 contain an authorization vulnerability allowing authenticated users to assign workflows to folders in other projects, bypassing project and folder authorization controls via manipulated request payloads during workflow creation.

Weaknesses (CWE)

CWE-639Authorization Bypass Through User-Controlled KeyCWE-89Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')CWE-1321Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')CWE-346Origin Validation ErrorCWE-522Insufficiently Protected Credentials

Risk Scores

CVSS 3.1
5.0/10
Medium · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:N/I:L/A:N

Affected Products

VendorProductVersionsPlatforms
n8nvers:unknown/*

References

advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory
advisory

Browse GCVE Records

74,581 records in the GCVE database · Updated July 24, 2026

No matching records found.

Explore Further

Investigate this vulnerability in the interactive console or download the raw GCVE record.

$ Console Community · 100/wk Open console ›