n8n Token Exchange: Briefly the World’s Worst Valet
The n8n token exchange worked – briefly – like a parking valet attendant who follows one rule: anyone allowed to look at a claim ticket is also allowed to replace the car attached to it. That’s more or less what happened inside n8n’s OAuth credential reconnect process. The flaw, now tracked as CVE-2026-45732, was published by n8n through a GitHub security advisory on May 13, 2026. The National Vulnerability Database added the CVE record on June 23. It received a high-severity CVSS 4.0 score of 8.3. It’s unclear how long the authorization flaw remained in n8n before researchers found it. The public advisory identifies the patched releases and its May 13, 2026 disclosure date, but doesn’t provide the original introduction … Read more