CVE-2026-33720 identifies an authorization bypass vulnerability in n8n, an open-source workflow automation platform, affecting versions prior to 2.8.0. This flaw occurs when the non-default N8N_SKIP_AUTH_ON_OAUTH_CALLBACK environment variable is set to true, allowing an attacker to trick a victim into storing their OAuth tokens in the attacker's credential, enabling unauthorized workflow execution. Rated as Medium severity (CVSS 4.2), the vulnerability has a network attack vector but high attack complexity, requiring user interaction and leading to low impact on confidentiality and integrity. There is currently no evidence of active exploitation, nor are public exploit codes available, with minimal community discussion observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.0CPE matchmatch criteria | cpe:2.3:a:n8n:n8n:*:*:*:*:*:node.js:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:L/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.2 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.2 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.