n8n Token Exchange Flaw Lets Attackers Log In As Other Users
n8n patched a bug in their Enterprise token exchange feature that let attackers log in as other users without passwords. The flaw ignored the JWT issuer claim, matching users on subject alone. Strix's AI security agent found it.
Read more →