vulns.co
/
GKData.io MCP

n8n · 2 min read

n8n: refreshed authority must remain bound to the consented resource

The maintainer reports that initial OAuth authorization preserved resource-specific consent, while refresh grants checked registration without preserving that binding. A client could consequently receive authority over another workflow accessible to the consenting user. This is a delegated-consent failure; the source does not establish access beyond that user’s underlying permissions or a production incident.

Open the reference Maintainer AdvisoryReviewed 2026-10-03

How to use this reference

The stated repair retains the granted resource in refresh-token state and rejects conflicting resource choices. The maintainer also calls for renewed authorization after upgrading because older refresh tokens lack this binding; temporary restrictions are incomplete mitigation. Editorial lesson: review authorization invariants throughout a grant’s lifecycle, including migration of pre-fix state.

Before reading

  • OAuth grant, refresh, resource, and consent concepts
  • Distinguishing a user’s permissions from the smaller authority delegated to a client

Context and limits

  • CVE-2026-86073. The advisory credits bariskececi as reporter; Matsuuu is its publishing maintainer.
  • Prerequisites include client registration, authenticated user consent for one protected workflow, and another identifiable workflow within that user’s execution permissions.
  • The patched-version table lists 2.38.2 and 2.37.7, while prose says 2.38.1 and 2.37.7. No corrected affected interval is inferred.
  • Official release pages date both 2.38.2 and 2.37.7 to September 2, 2026, separately from September 3 advisory publication; 2.38.2 is labeled pre-release. Release existence does not resolve the advisory inconsistency.
  • No bounty is established. Learning prerequisites and general design guidance are editorial.

Related visual models

Sources and provenance

  1. Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution n8n · reviewed 2026-10-03
  2. n8n@2.38.2 release n8n · reviewed 2026-10-03
  3. n8n@2.37.7 release n8n · reviewed 2026-10-03

Record reviewed 2026-10-03. Snapshot d5550c789111. Open the complete JSON contract.

GitHub snapshot 2026-10-04

d5550c789111 · JSON exports & schemas · CC BY 4.0 content / MIT software