n8n Token Exchange Flaw Could Let Attackers Log In as Users From Another Issuer

A Critical Flaw in n8n Token Exchange System Puts Users at Risk of Account Takeover

A severe security vulnerability has been discovered in the token exchange system of n8n, an open-source workflow automation platform widely used by developers and organizations. The flaw allows attackers to hijack user accounts from other issuers, compromising sensitive data and potentially leading to identity theft.

The issue stems from a misconfigured API endpoint that enables unauthorized access to tokens, which serve as digital keys for authenticating users within the n8n ecosystem. When an attacker gains possession of a valid token, they can impersonate the associated user account, gaining full access to their connected applications and data. The vulnerability affects any organization using n8n’s token exchange system, including those that have integrated it with other services.

To understand how this works, consider a scenario where a company uses n8n to manage workflows between different teams or third-party services. Each user is assigned a unique token to authenticate their interactions within the platform. If an attacker exploits the vulnerability, they can steal these tokens and use them to log in as the targeted users from other issuers. This would grant access to sensitive data, such as company secrets, intellectual property, or even financial information.

The severity of this issue lies not just in its potential for account takeover but also in its ease of exploitation. The vulnerability is particularly concerning due to n8n’s widespread adoption and the fact that it is an open-source platform. As AI-driven threat detection continues to grow in prominence, it’s worth noting that this flaw was likely discovered by a security researcher using automated tools.

The incident serves as a stark reminder of the importance of regular security audits and vulnerability assessments. Even for organizations with robust cybersecurity measures in place, unexpected vulnerabilities can still emerge. To protect against similar threats, we recommend implementing continuous monitoring solutions that track API endpoints and flag unusual activity. Furthermore, staying informed about the latest security patches and updates will help minimize exposure to potential attacks.

For individuals using n8n, it’s essential to change your token periodically and monitor for any suspicious login attempts. If you suspect a breach, immediately report the incident to your organization’s IT department or cybersecurity team.


Source: The Hacker News — 2026-07-16