n8n
cpe:2.3:a:n8n:n8n:*:*:*:*:node.js:*:*
- < 2.28.0
A vulnerability exists in n8n versions prior to 2.28.0, allowing authenticated users to improperly assign workflows to folders in other projects. This issue arises from a failure to enforce proper authorization, enabling users to bypass project and folder boundaries by sending crafted request payloads during workflow creation. As a result, logical integrity violations occur in the folder structures of the targeted projects.
Exploitation of this vulnerability allows for unauthorized workflow assignments, leading to logical integrity violations in the affected project's folder structure at the database level.
Users should upgrade to n8n version 2.28.0 or later. If an immediate upgrade is not possible, project membership and workflow creation permissions should be restricted to trusted users as a temporary mitigation.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.