VYPR
Medium severityNVD Advisory· Published Sep 8, 2026

CVE-2026-86077

CVE-2026-86077

Description

n8n is an open source workflow automation platform. Prior to 2.37.7 and 2.38.2, the /chat WebSocket route accepted a resumeToken and resumed a paused execution without checking that the target node supported chat messages. An anonymous form submitter who received that token could reuse it on the chat route to release a Send-and-Wait, non-chat HITL, or Wait approval gate. The affected authorization logic is packages/cli/src/chat/chat-execution-manager.ts, where canResumeOverChat did not gate the resume target. This issue is fixed in versions 2.37.7 and 2.38.2.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1
  • N8n Io/N8nllm-fuzzy
    Range: <2.37.7 and <2.38.2

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.