{"id":"CVE-2026-56353","aliases":["GHSA-jh8h-6c9q-7gmw"],"url":"https://o3.security/vulnerability/CVE-2026-56353","summary":"n8n - Authentication Bypass in Chat Trigger Node","details":"n8n contains an authentication bypass in the Chat Trigger node when configured with n8n User Auth (a non-default configuration). In affected releases — before 1.123.22, the 2.0.0 through 2.9.2 line, and 2.10.0 — the authentication check on the Chat Trigger webhook endpoint can be circumvented, allowing access without valid credentials. Fixed in 1.123.22, 2.9.3, and 2.10.1.","published":"2026-07-15T11:25:29.334Z","modified":"2026-08-12T03:51:31.840453416Z","cvss":null,"epss":{"score":0.0033,"percentile":0.25342,"asOf":"2026-08-24"},"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"npm","name":"n8n","fixedVersion":"1.123.22"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.9.3"},{"ecosystem":"npm","name":"n8n","fixedVersion":"2.10.1"}],"fix":null,"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/56xxx/CVE-2026-56353.json"},{"type":"ADVISORY","url":"https://github.com/n8n-io/n8n/security/advisories/GHSA-jh8h-6c9q-7gmw"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-56353"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/n8n-authentication-bypass-in-chat-trigger-node"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-12T03:51:31.840453416Z"}}