Impact
n8n prior to 2.39.6 and 2.40.0 before 2.40.1 contain an unescaped parameter interpolation flaw in SendGrid, Freshservice, and ServiceNow nodes that lets an attacker break out of query literals. The flaw permits filter bypass, turning single‑lookups into match‑all queries which can expose bulk data such as contact lists, tickets, and directory entries.
Affected Systems
Vendor n8n‑io, product n8n. Affected versions include any release before 2.39.6 and any 2.40.0 before 2.40.1.
Risk and Exploitability
The CVSS score of 6.9 indicates moderate severity. EPSS is not available and the vulnerability is not in the CISA KEV catalog. Attackers can exploit the flaw by binding node parameters to untrusted external data; if the node is reachable over the network and the input is not sanitized, they may gain access to sensitive bulk data. The attack likely requires some level of access to configure or trigger a workflow that uses the vulnerable nodes.
OpenCVE Enrichment