PT-2026-36900 · N8N · N8N

34Selen

·

Published

2026-04-22

·

Updated

2026-05-05

·

CVE-2026-42228

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions n8n versions prior to 1.123.32 n8n versions prior to 2.17.4 n8n versions prior to 2.18.1
Description The '/chat' WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature fails to verify if an incoming connection is authorized to interact with the target execution. An unauthenticated remote attacker who identifies a valid execution ID for a workflow in a waiting state can attach to that execution, receive the pending prompt intended for the legitimate user, and submit arbitrary input to resume or influence downstream workflow behavior.
Recommendations Update to version 1.123.32. Update to version 2.17.4. Update to version 2.18.1.

Exploit

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

BDU:2026-06921
CVE-2026-42228
GHSA-F77H-J2V7-G6MW

Affected Products

N8N