THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cw9w-vv67-hf73 (medium) — n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

[GHSA] GHSA-cw9w-vv67-hf73 (medium) — n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

medgithub_advisoriesPublished 2026-09-10

GHSA-cw9w-vv67-hf73 Severity: medium CVE: CVE-2026-86073

n8n: Per-Resource OAuth Consent Bypass via Unbound Refresh Token Resource Substitution

## Impact

The OAuth token endpoint bound an authorization code's first access token to the consented resource, but not its refresh token. Refreshing only checked that the requested resource was registered, not that it matched the original grant. An OAut

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cw9w-vv67-hf73