Impact
The Guardrail node in n8n contains an input validation flaw (CWE‑20) that allows attackers to supply crafted data to override default guardrail rules. This can break the intended workflow logic, enabling unintended execution of actions and thereby compromising the integrity of the automation process.
Affected Systems
All installations of the n8n workflow automation platform built on Node.js using versions prior to 2.10.0 are affected.
Risk and Exploitability
The CVSS score of 6.3 reflects moderate severity, while the EPSS score of less than 1% indicates a low likelihood of real‑world exploitation. The vulnerability is exercised via crafted input in the workflow creation or editing interface; attackers must have the ability to modify workflow definitions. No explicit network exposure or additional privileges are mentioned, so the risk is limited to users with permissions to edit workflows.
OpenCVE Enrichment