Impact
A path traversal vulnerability exists in the n8n node of n8n versions before 1.123.80, 2.39.6, and 2.40.1 because resource identifiers are not properly validated. Attackers can construct malicious resource IDs that redirect API calls to unintended resources, giving the attacker unauthorized visibility into workflows, executions, and credential secrets that fall within the scope of the credentialed API key used for the request. The flaw therefore allows an attacker to read, modify, or delete sensitive automation data and secrets that were otherwise protected by the API key’s access controls.
Affected Systems
The vulnerability affects n8n-io’s n8n product. It is present in every release prior to 1.123.80, prior to 2.39.6, and prior to 2.40.1, inclusive of all earlier 2.x versions.
Risk and Exploitability
The CVSS score of 8.1 indicates a high impact, while the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Exploitation requires remote delivery of crafted API requests that include the vulnerable node; the attacker must have an API key with permissions that cover the target workflow or credential resources. The likely attack vector is over the network, leveraging the exposed n8n API. Because the flaw permits access to sensitive data within the key’s privilege set, it can lead to data exfiltration or compromise of automation logic while targeting a single n8n deployment.
OpenCVE Enrichment