Impact
The vulnerability allows an attacker who can register a resolver to set a fallback resolver that points to an attacker‑controlled endpoint during the account connection flow, causing the Dynamic Credentials authorize and revoke endpoints to expose session tokens. This leakage of session tokens enables the attacker to access collaborators’ credentials without authorization, representing a credential‑leak weakness that compromises confidentiality and integrity of user accounts.
Affected Systems
The affected product is n8n, specifically all versions before 2.39.6 and the 2.40.x series prior to 2.40.1.
Risk and Exploitability
The CVSS score of 8.5 classifies the flaw as high severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Exploitation requires the ability to register a resolver, implying privileged or internal access. Once a fallback resolver is configured, any user interacting with the dynamic credential flow can have their session tokens intercepted, allowing the attacker to impersonate or reuse those sessions. The flaw is API‑based, so a remote adversary with registrar privileges could exploit it remotely.
OpenCVE Enrichment