HIGH 8.5 NVD
CVE-2026-103259
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Att
n8n versions before 2.39.6 and 2.40.0 before 2.40.1 contain a session token leakage vulnerability in the Dynamic Credentials authorize and revoke endpoints. Attackers with resolver registration capability can capture collaborators' session tokens by setting a fallback resolver to an attacker-controlled endpoint during the account connection flow, enabling unauthorized credential access.
References
- https://github.com/n8n-io/n8n/security/advisories/GHSA-rx55-8qhx-4hwx
- https://www.vulncheck.com/advisories/n8n-before-2.39.6-and-2.40-x-before-2.40.1-session-to
This high severity vulnerability with a CVSS score of 8.5 was published on 2026-10-01 via NVD.
vulnfeed aggregates 12641 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.