Impact
The vulnerability allows the circumvention of the preAuthentication Hook’s host validation, enabling an attacker with credential update rights to modify the host entry so that stored username‑password credentials for Wekan and Baserow are transmitted in cleartext to an arbitrary, attacker‑controlled host. The result is a leak of the credentials that can be used to compromise services that rely on them, threatening account confidentiality and potentially the integrity of downstream systems. The flaw is a credential storage confidentiality issue (CWE‑522).
Affected Systems
The affected product is n8n, versions before 2.39.6 and before 2.40.1 for the 2.40.x line. All installations using the preAuthentication Hook and hosting credentials for Wekan or Baserow are vulnerable unless upgraded to the specified patched releases.
Risk and Exploitability
The CVSS score of 7.1 indicates a high risk with significant impact. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower public exploitation probability but a still serious threat. Attackers need existing credential‑update permissions to exploit the flaw; once permissions are available, they can redirect credentials to any host, making the flaw an effective tool for credential exfiltration.
OpenCVE Enrichment