Impact
The vulnerability is an authorization bypass in the credential test endpoint that permits an attacker to specify an arbitrary project ID in the request body. By doing so, the endpoint resolves project‑scoped variables and forces them to be sent to a host specified by the attacker. This allows the exfiltration of sensitive data such as passwords or API keys, representing a clear confidentiality breach. The weakness is captured by CWE‑639, a classic information disclosure issue.
Affected Systems
It affects all installations of n8n running any version before 1.123.80, including 2.0.0 through 2.39.5, and the 2.40.0 series up to 2.40.0 inclusive. Version 2.40.1 and later are known to contain the fix.
Risk and Exploitability
The CVSS score of 7.1 marks it as a high‑impact vulnerability, yet no EPSS data is available and it is not listed in CISA's KEV catalog, suggesting no widespread exploitation yet. Likely, an attacker must be able to send crafted HTTP requests to the credential test endpoint, either internally or externally if the API is exposed. Successful exploitation results in disclosure of project‑specific secrets, which could lead to broader compromise of connected services. Given the severity and the potential for data leakage, immediate remediation is recommended.
OpenCVE Enrichment