CVE-2026-77073

Source
https://cve.org/CVERecord?id=CVE-2026-77073
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77073.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-77073
Aliases
  • GHSA-vfrj-582q-mvcp
Downstream
Published
2026-08-20T11:21:08Z
Modified
2026-09-03T03:48:20Z
Severity
  • 5.3 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N CVSS Calculator
Summary
n8n before 2.34.1 Cross-Project Credential Access via MCP
Details

n8n versions before 2.34.1 contain a credential validation bypass in the MCP create_workflow_from_code tool when authentication type is set to an expression. Attackers with a valid MCP Bearer API key and knowledge of a target credential ID can persist unauthorized cross-project credential references on workflows in different projects.

Database specific
{
    "cna_assigner": "VulnCheck",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/77xxx/CVE-2026-77073.json"
}
References

Affected packages

Git / github.com/n8n-io/n8n

Affected ranges

Type
GIT
Repo
https://github.com/n8n-io/n8n
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "2.34.0"
        },
        {
            "fixed": "2.34.1"
        },
        {
            "introduced": "2.0.0"
        },
        {
            "fixed": "2.33.4"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

2.*
2.34.0
n8n@2.*
n8n@2.34.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-77073.json"