Количество 2
Количество 2
CVE-2026-59208
n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1.
GHSA-mq3m-f8x3-579w
n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution
Уязвимостей на страницу
Уязвимость | CVSS | EPSS | Опубликовано | |
|---|---|---|---|---|
CVE-2026-59208 n8n is an open source workflow automation platform. Prior to 2.27.4 and from 2.28.0 prior to 2.28.1, n8n instances configured with more than one trusted token-exchange issuer resolved external identities to local accounts using only the JWT sub claim and ignored the iss claim, allowing an attacker with a valid token from one trusted issuer and a sub matching a victim under another issuer to authenticate as that victim. This issue is fixed in versions 2.27.4 and 2.28.1. | CVSS3: 6.8 | 3% Низкий | около 2 месяцев назад | |
GHSA-mq3m-f8x3-579w n8n: Cross-Issuer Token Exchange Account Binding via Subject-Only Identity Resolution | 3% Низкий | около 1 месяца назад |
Уязвимостей на страницу