mediumVulnerability

CVE-2026-86085

## Impact The endpoints `/rest/roles/:slug/assignments` and `/rest/roles/:slug/assignments/:projectId/members` checked only that the caller could manage the role type, not that they could see the project named in the request. A user holding role-management permission could therefore name any project on the instance and read back its members' names and email addresses. The patch adds a project-access check to both routes, hiding projects the caller cannot see and returning not-found for a project it cannot list. ## Patches The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Audit and revoke any custom global roles that carry the `role:manageProject` scope, limiting that scope to fully trusted users only. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Properties

ghsa_id
GHSA-cqr2-h44g-v75v
severity
medium
summary
n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints
epss_score
0.00263
cve_id
CVE-2026-86085
is_ghsa_only
false
ghsa_published
2026-09-10T21:13:24Z
source_url
https://github.com/advisories/GHSA-cqr2-h44g-v75v
epss_percentile
0.18151
ghsa_updated
2026-09-10T21:13:25Z

Related Entities (5)

ENRICHED_BY (1)

[Source]FIRST EPSS

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/n8n

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Missing Authorization

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-86085 — Ninja Signal Threat Intelligence | Ninja Signal