mediumCVSS 6.4Vulnerability

GHSA-h3jj-5f3v-3685

## Impact The Public API endpoint for retrying executions authorized access using `workflow:read` rather than `workflow:execute`. An authenticated user with read-only access to a shared workflow could use the Public API to retry executions of that workflow, bypassing the intended permission boundary between read and execute access. This issue affects instances where workflows are shared with other users or across projects. ## Patches The issue has been fixed in n8n versions 2.25.7, and 2.26.2. Users should upgrade to one of these versions or later to remediate the vulnerability. ## Workarounds If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict workflow sharing to fully trusted users only. - Restrict network access to the n8n Public API to trusted users only. These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Properties

ghsa_id
GHSA-h3jj-5f3v-3685
severity
medium
summary
n8n: Public API Execution Retry Authorization Bypass
cvss_score
6.4
cve_id
GHSA-h3jj-5f3v-3685
cvss_vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:N
is_ghsa_only
true
ghsa_published
2026-06-16T22:40:06Z
source_url
https://github.com/advisories/GHSA-h3jj-5f3v-3685
ghsa_updated
2026-06-16T22:40:07Z

Related Entities (4)

AFFECTS (1)

[Software]npm/n8n

HAS_WEAKNESS (1)

[Weakness]Incorrect Authorization

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (1)

[Software]npm/n8n

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-h3jj-5f3v-3685 (CVSS 6.4) — Ninja Signal Threat Intelligence | Ninja Signal