VDB
Sign up
MEDIUM

GHSA-cqr2-h44g-v75v

n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

Quick fix

GHSA-cqr2-h44g-v75v — n8n: upgrade to the fixed version with the command below.

npm install n8n@2.38.2

Details

## Impact

The endpoints `/rest/roles/:slug/assignments` and `/rest/roles/:slug/assignments/:projectId/members` checked only that the caller could manage the role type, not that they could see the project named in the request. A user holding role-management permission could therefore name any project on the instance and read back its members' names and email addresses. The patch adds a project-access check to both routes, hiding projects the caller cannot see and returning not-found for a project it cannot list.

## Patches

The issue has been fixed in n8n versions 2.38.2 and 2.37.7. Users should upgrade to one of these versions or later to remediate the vulnerability.

## Workarounds

If upgrading is not immediately possible, administrators should consider the following temporary mitigations: - Restrict n8n instance access to fully trusted users only. - Audit and revoke any custom global roles that carry the `role:manageProject` scope, limiting that scope to fully trusted users only.

These workarounds do not fully remediate the risk and should only be used as short-term mitigation measures.

Are you affected?

Enter the version of the package you're using.

Affected packages

npm/n8n
Introduced in: 2.38.0Fixed in: 2.38.2
Fixnpm install n8n@2.38.2
npm/n8n
Introduced in: 0Fixed in: 2.37.7
Fixnpm install n8n@2.37.7

References