CVE-2026-42228 is an authorization flaw in n8n affecting the Chat Trigger node's Hosted Chat feature. In versions prior to 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint did not verify whether an incoming connection was authorized to interact with the targeted workflow execution. As a result, an unauthenticated remote attacker who knows or can determine a valid execution identifier for a workflow that is paused in a waiting state can attach to that execution over WebSocket. The attacker can then receive the pending prompt intended for the legitimate participant and submit arbitrary input that resumes the execution or alters downstream workflow logic.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a functional exploit PoC for CVE-2026-42228 / GHSA-f77h-j2v7-g6mw affecting n8n chat workflows. It is not tied to a major exploit framework; instead it contains a standalone Python exploit, a Bash helper script, and Docker artifacts for spinning up a reproducible lab. Repository structure: (1) poc_GHSA-f77h-j2v7-g6mw.py is the main exploit and primary entry point; (2) exploit.sh wraps common operations such as setup, scanning execution IDs, attacking a known execution ID, viewing logs, and cleanup; (3) docker-compose.yml provisions a vulnerable n8n container (n8nio/n8n:1.123.22) plus the attacker container on a shared Docker network; (4) Dockerfile builds the attacker image with websocket-client installed; (5) README.md documents the vulnerability, prerequisites, and usage. Main exploit capability: the Python PoC builds an unauthenticated WebSocket connection to the n8n /chat endpoint using a guessed or known executionId and a generated sessionId. It probes execution IDs over a range or attacks a specific execution directly. If the server indicates the execution is in a waiting state (notably via the n8n|continue message), the exploit can observe pending messages/prompts and then send a crafted JSON message with action=sendMessage and attacker-controlled chatInput. This resumes the workflow using attacker-supplied input, effectively hijacking the legitimate chat execution. Operational flow in code: ws_url() converts a supplied base URL into ws:// or wss:// and appends /chat?sessionId=...&executionId=...&isPublic=true. probe_execution() opens the WebSocket, handles heartbeat traffic, interprets server responses to distinguish not_found vs waiting states, and if waiting sends the hijack payload. scan() iterates sequential execution IDs to find waiting executions and optionally injects into each one found. single() attacks one specified execution ID. The exploit is more than a detector: it actively injects data into vulnerable executions. However, the payload is basic and operator-supplied text rather than a full post-exploitation shell or framework-integrated payload, so OPERATIONAL is the best maturity fit. Notable target/lab configuration from docker-compose.yml: the vulnerable service disables user management and basic auth, allows any CORS origin, persists execution data in SQLite, and exposes port 5678. These settings support demonstration of the unauthenticated chat hijack scenario but are not all strictly required beyond the vulnerable chat workflow conditions described in the README.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.