PT-2025-27010 · N8N · N8N
Tatianahub
·
Published
2025-06-26
·
Updated
2025-09-02
·
CVE-2025-49592
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
n8n versions prior to 1.98.0
Description:
The issue is an Open Redirect vulnerability in the login flow, affecting authenticated users who can be redirected to untrusted domains after logging in. This is achieved by crafting malicious URLs with a misleading redirect query parameter, potentially leading to phishing attacks, credential or 2FA theft, and reputation risk. The vulnerability affects anyone hosting n8n and exposing the "/signin" endpoint to users.
Recommendations:
For versions prior to 1.98.0, upgrade to version 1.98.0 or later, which introduces strict origin validation for redirect URLs, ensuring only same-origin or relative paths are allowed after login.
Exploit
Fix
Open Redirect
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
N8N