CyberRota Analysis
AI-GeneratedThe Chat Trigger node in n8n, when configured with n8n User Auth, is vulnerable to an authentication bypass, allowing unauthorized access to the webhook endpoint without valid credentials. This issue affects versions prior to 1.123.22 and 2.9.3, as well as the 2.10.0 release. Organizations utilizing n8n with this configuration should prioritize updating to the patched versions to mitigate potential security risks.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.
Related CVEs
Other vulnerabilities affecting the same vendor(s)