n8n: Improper Authorization Allows Authenticated Users to Assign Workflows to Folders in Other Projects
MediumCVE-2026-59253 · Published Jul 22, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| n8n npm | < 2.28.0 | 2.28.0 |
Details and references
## Impact An authenticated user with permission to create workflows in one project could bypass project/folder authorization boundaries during workflow creation. By supplying a crafted request payload, the user could associate a newly created workflow with a folder belonging to a different project they do not have access to. The workflow itself remains in the attacker's project and is not visible to the target project's members. The target project's folder ownership is not changed, and no data from the target project is exposed. The impact is limited to a logical integrity violation of the target project's folder structure at the database level. This issue affects instances with multi-project and folder support enabled. ## Patches The issue has been fixed in n8n version 2.28.0. Users should upgrade to this version or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict project membership and workflow creation permissions to fully trusted users only. This workaround does not fully remediate the risk and should only be used as a short-term mitigation measure.
- CVSS 4.0
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-639
- Also known as
- CVE-2026-59253
More n8n advisories
All n8n| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 22 | n8n: AI Agents Project Viewer Privilege Escalation via run_node_tool CVE-2026-65015Highfixed in 2.29.8, 2.30.1 | High | 2.29.8, 2.30.1 |
| Jul 22 | n8n: Race Condition in Git Clone Node Allows Authenticated Users to Achieve Remote Code Execution CVE-2026-65598Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: DOM-Based XSS via Unsandboxed iframe srcdoc in HTML Preview CVE-2026-65597Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Stored DOM XSS via Resource Locator `cachedResultUrl` CVE-2026-65592Highfixed in 1.123.64, 2.29.8, 2.30.1 | High | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Google Service Account Private Key Exposed in JWT Header CVE-2026-65599Mediumfixed in 1.123.64, 2.29.8, 2.30.1 | Medium | 1.123.64, 2.29.8, 2.30.1 |
| Jul 22 | n8n: Shared Credential Header Leak via HTTP Request Pagination Expression CVE-2026-59209Highfixed in 1.123.61, 2.27.4, 2.28.1 | High | 1.123.61, 2.27.4, 2.28.1 |