news.mlab.sh
5 results
vulnerability

n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

A vulnerability in n8n’s Enterprise token exchange feature allows attackers to log in as users from another issuer if the platform trusts more than one external token issuer. The flaw stems from a mismatch between the issuer and subject claims in the JWT, leading to a single n8n account being impersonated. The vulnerab…

The Hacker News · Jul 16, 2026 High