THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-cqr2-h44g-v75v (medium) — n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

[GHSA] GHSA-cqr2-h44g-v75v (medium) — n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

medgithub_advisoriesPublished 2026-09-10

GHSA-cqr2-h44g-v75v Severity: medium CVE: CVE-2026-86085

n8n: Cross-Tenant Project-Member PII Disclosure via Missing Per-Project Scope Check on Role Assignment Endpoints

## Impact

The endpoints `/rest/roles/:slug/assignments` and `/rest/roles/:slug/assignments/:projectId/members` checked only that the caller could manage the role type, not that they could see the project named in the request. A

MITRE ATT&CK techniques

Indicators of compromise

Original source: https://github.com/advisories/GHSA-cqr2-h44g-v75v