Impact
n8n versions released before 1.123.80 allow an attacker who can edit a shared workflow to tamper with credentials by creating duplicate node identifiers. The workflow credential tamper guard is bypassed when an attacker supplies a node name that differs from its ID, enabling the attacker to retain the victim’s credentials and direct them to a host controlled by the attacker, thereby revealing sensitive secrets.
Affected Systems
The vulnerability affects all installations of n8n-io:n8n up to, but not including, version 1.123.80. Any instance running a workflow that permits editor access from other users is potentially impacted.
Risk and Exploitability
The CVSS score of 5.8 indicates a moderate impact, and the EPSS score is not available, so the probability of public exploitation cannot be quantified. The vulnerability is not listed in the CISA KEV catalog. Attackers would need editor-level permissions on a shared workflow and would exploit the mismatch between node IDs and names; the likelihood of exploitation depends on the number of shared workflows with insufficient permission controls.
OpenCVE Enrichment