CVE-2026-42235Disclosure(n8n / n8n)

LOWCVSS 9.6 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch n8n n8n systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth client with a crafted client_name. If a victim user authorized the OAuth consent dialog and a second user subsequently revoked that access, a toast notification would render the injected script. Clicking the link would execute arbitrary JavaScript in the victim's authenticated n8n browser session, enabling credential and session token theft, workflow manipulation, or privilege escalation. This issue has been patched in versions 1.123.32, 2.17.4, and 2.18.1.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79CWE-87

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • n8n

Threat summary

  • Patch or workaround signal is available
  • 7 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 6 signals
  • Disclosure: 4 classified signals
  • General: 3 classified signals
  • Peaked at 5 mentions on most recent observed day (2026-05-13)
  • 7 total mentions across 3 days

Affected systems

Vendors
Products
n8n

1 version affected across 1 product

Deep dive

Activity timeline7 mentions / 3d
01345Mentions · 2026-05-04: 1Mentions · 2026-05-05: 1Mentions · 2026-05-13: 5Patch / Workaround · 2026-05-04: 1Technical Details · 2026-05-04: 1Technical Details · 2026-05-05: 1Technical Details · 2026-05-13: 405-0405-0505-13
Signal classification2 categories
Disclosure
457.1%
General
342.9%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-05-041
Disclosure1
2026-05-051
Disclosure1
2026-05-135
Disclosure2General3
Full discourse7 posts
  • Lyrie.ai@lyrie_ai
    General

    CVE: CVE-2026-42235 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory n8n is an open source workflow automation platform.

    Post summary

    A critical CVE (CVE‑2026‑42235) affecting n8n has been identified with a high CVSS score, but no exploitation or mitigation details are provided.

    2001037
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    --- Validated by the Lyrie Threat Intelligence Pipeline — 3 independent sources confirmed before publication. No speculation. CVE: CVE-2026-42235 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    Stakeholders are informed of a newly identified critical vulnerability, CVE-2026-42235, with a CVSS score of 9.6 and severity label CRITICAL.

    1000030
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    Disclosure

    CRITICAL: CVE-2026-42235 (CVSS 9.6) — n8n n8n. CVE: CVE-2026-42235 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The post announces a critical vulnerability (CVE‑2026‑42235) with CVSS 9.6 for n8n, but provides no PoC, exploit, or patch details.

    1000028
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    References CVE: CVE-2026-42235 CVSS: 9.6 (3.1) — CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H Severity: CRITICAL Status: Critical advisory

    Post summary

    The text reports a critical severity advisory for CVE-2026-42235, including its CVSS score and vector, but provides no PoC, exploit, active usage, or mitigation information.

    1000029
    210 followersView on X
  • Lyrie.ai@lyrie_ai
    General

    https://lyrie.ai/research/research/cve-2026-42235-n8n-n8n #lyrie #cybersecurity #CVE #threatintel #zerodayattack

    Post summary

    The post references a link to research on CVE‑2026‑42235 in n8n, but it contains no explicit technical details, PoC, patch information, or evidence of active exploitation.

    0000022
    210 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-42235 Unauthenticated Cross-Site Scripting via MCP OAuth Client Registration i... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-42235 Vulnerability Notification: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=3

    Post summary

    The tweet announces CVE‑2026‑42235, describing it as an unauthenticated XSS flaw in MCP OAuth client registration, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000043
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-42235 n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an unauthenticated attacker could register a malicious MCP OAuth c… https://www.cve.org/CVERecord?id=CVE-2026-42235

    Post summary

    The CVE-2026-42235 vulnerability in n8n allows unauthenticated attackers to register malicious OAuth clients in versions prior to 1.123.32, 2.17.4, and 2.18.1, and the issue has been addressed in later releases.

    00000163
    57.4K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appn8nn8n-node.js-
Appn8nn8n2.18.0node.js-

Explore more