THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-35jj-42hp-8gmq (medium) — n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

[GHSA] GHSA-35jj-42hp-8gmq (medium) — n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

medgithub_advisoriesPublished 2026-09-10

GHSA-35jj-42hp-8gmq Severity: medium CVE: CVE-2026-86077

n8n: Anonymous Approval-Gate Bypass via Reused resumeToken over the Chat WebSocket

## Impact

The `/chat` WebSocket route resumed a paused execution from a resume token without checking that the node being resumed was a chat node. n8n hands that token to anonymous form submitters, so a party with no account could present it on the chat rou

Indicators of compromise

Original source: https://github.com/advisories/GHSA-35jj-42hp-8gmq