As cited
Copy frozen at (site build).
vulnerabilities
n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer
n8n, a workflow automation platform, contained a JWT validation flaw in Enterprise instances configured with multiple external token issuers. The vulnerability allowed an attacker with a valid token from one issuer to gain unauthorized access to another user's account by exploiting weak claim matching that validated only the subject (sub) claim while ignoring the issuer (iss) claim.
Why it matters: Enterprise customers using n8n with multiple federated identity providers face account takeover risk; teams should audit token issuer configurations and apply fixes immediately.
- Source published
- First seen by Cybersecurity Tracker